Thousands Of Dropbox Accounts Breached In ‘Verification’ Hack
Hackers were able to gain access to approximately 5,000 Dropbox accounts last month after exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs.Â

According to a notification sent to the affected users, “an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address” – in some cases, users didn’t even have Lenovo accounts. The hackers then used the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without needing the login password, BleepingComputer notes.Â
The accounts were accessed August 4th through the 21st.Â
so dropbox got hacked (never had a Lenovo account, haven’t been to UK) pic.twitter.com/UoYRaJFuEC
— yoni | parser.eth (@yonilevy) August 31, 2026
Users reported receiving strange notifications “about two weeks ago,” urging them to change their password and activate two-factor authentication (2FA).Â
“One odd thing at the time: the Dropbox login page had started offering ‘Continue with SSO’ for my email even though I never created a Lenovo ID,” according to one person.Â
Lenovo told BleepingComputer that the issue was connected to a legacy integration between Lenovo ID and Dropbox, which was used “to improperly authenticate certain Dropbox accounts.”
“Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk,” the spokesperson continued.Â
Dropbox forced all sessions authenticated via Lenovo ID to expire, and added a new login requirement forcing users to use their Dropbox account password instead.Â
Tyler Durden
Wed, 09/02/2026 – 14:00Â Â
