← All stories
● Covered by 2 sources · 3 reportsMedium impact3 negative

Dropbox users affected by security breach due to SSO authentication flaw

🔄 Updated 30d ago — new reporting from 9to5Mac, BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Unauthorized access to Dropbox accounts occurred August 4-21, 2026.
  • Breach exploited a flaw in Lenovo ID single sign-on integration.
  • Attackers registered Lenovo IDs using target emails due to missing verification.
  • Dropbox implicitly linked rogue Lenovo IDs to existing accounts without password.
  • 5,000 Dropbox accounts were compromised.
  • Files were downloaded from 1,500 compromised accounts.
  • Developer Yoni Levy posted a copy of the email on X.

Unauthorized Access to Dropbox Accounts

Dropbox has informed multiple users about unauthorized access to their accounts that took place between August 4 and August 21, 2026. While Dropbox logs indicate no files were viewed or downloaded, the company is notifying affected users about the incident and steps they can take.

Root Cause: Single Sign-On Vulnerability

The breach originated from a vulnerability in Dropbox's single sign-on (SSO) integration with Lenovo IDs. Dropbox partners with Lenovo as an identity provider, allowing users to log in using verified Lenovo IDs. The core issue was identified as a flaw in Lenovo's email verification process, which permitted an unauthorized party to register a Lenovo ID using a victim's email address without requiring inbox access.

Dropbox's Authentication Failure

While Dropbox attributed the flaw to Lenovo's verification, a critical contributing factor was Dropbox's own authentication procedure. Dropbox did not require users to verify the new SSO link with their existing login credentials. This allowed the system to implicitly link the newly created, unverified Lenovo ID to an existing Dropbox account based solely on the email address, bypassing password prompts or consent for linking a new identity.

Attack Vector Details

The attack involved several steps: attackers compiled target email addresses, registered rogue Lenovo IDs using these emails by exploiting the missing verification, and then used the 'Continue with Lenovo' option on Dropbox. Lenovo's authorization server issued a token, and Dropbox resolved the email claim to an existing account, creating a session without further authentication.

Impact and Takeaways

This incident underscores the security risks associated with federated identity management when proper verification and linking protocols are not rigorously enforced by all parties. It highlights the importance of multi-factor authentication and explicit user consent when linking new identity providers to existing accounts, even when relying on trusted third-party services.

Updates

🕒 2026-09-02 · new reporting from 9to5Mac, BleepingComputer
  • 5,000 Dropbox accounts were compromised.
  • Files were downloaded from 1,500 compromised accounts.
  • Developer Yoni Levy posted a copy of the email on X.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Dropbox has notified users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process. This vulnerability allowed attackers to register fraudulent Lenovo IDs using victims' email addresses, which were then used to log into linked Dropbox accounts without needing the Dropbox password. The incident highlights risks associated with third-party authentication integrations and impacts users whose Dropbox accounts were linked to Lenovo Identity Provider Services.

Dropbox notified users of unauthorized access to approximately 5,000 accounts, with files downloaded from 1,500 of them. The breach stemmed from a vulnerability in the single sign-on (SSO) process involving Lenovo IDs, where attackers could register a Lenovo ID with a victim's email without verification, then use it to access Dropbox accounts. This incident highlights critical flaws in federated authentication implementations, impacting user data security.

Dropbox notified users of unauthorized account access between August 4 and August 21, 2026, stemming from a vulnerability in its single sign-on (SSO) integration with Lenovo IDs. Attackers exploited a missing email verification step in Lenovo's process to create rogue Lenovo IDs, which Dropbox then implicitly linked to existing user accounts without further authentication. This incident highlights critical flaws in federated identity management and the need for robust verification during SSO setup.