← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Dropbox users affected by security breach due to SSO authentication flaw

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Unauthorized access to Dropbox accounts occurred August 4-21, 2026.
  • Breach exploited a flaw in Lenovo ID single sign-on integration.
  • Attackers registered Lenovo IDs using target emails due to missing verification.
  • Dropbox implicitly linked rogue Lenovo IDs to existing accounts without password.

Unauthorized Access to Dropbox Accounts

Dropbox has informed multiple users about unauthorized access to their accounts that took place between August 4 and August 21, 2026. While Dropbox logs indicate no files were viewed or downloaded, the company is notifying affected users about the incident and steps they can take.

Root Cause: Single Sign-On Vulnerability

The breach originated from a vulnerability in Dropbox's single sign-on (SSO) integration with Lenovo IDs. Dropbox partners with Lenovo as an identity provider, allowing users to log in using verified Lenovo IDs. The core issue was identified as a flaw in Lenovo's email verification process, which permitted an unauthorized party to register a Lenovo ID using a victim's email address without requiring inbox access.

Dropbox's Authentication Failure

While Dropbox attributed the flaw to Lenovo's verification, a critical contributing factor was Dropbox's own authentication procedure. Dropbox did not require users to verify the new SSO link with their existing login credentials. This allowed the system to implicitly link the newly created, unverified Lenovo ID to an existing Dropbox account based solely on the email address, bypassing password prompts or consent for linking a new identity.

Attack Vector Details

The attack involved several steps: attackers compiled target email addresses, registered rogue Lenovo IDs using these emails by exploiting the missing verification, and then used the 'Continue with Lenovo' option on Dropbox. Lenovo's authorization server issued a token, and Dropbox resolved the email claim to an existing account, creating a session without further authentication.

Impact and Takeaways

This incident underscores the security risks associated with federated identity management when proper verification and linking protocols are not rigorously enforced by all parties. It highlights the importance of multi-factor authentication and explicit user consent when linking new identity providers to existing accounts, even when relying on trusted third-party services.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~24 min · 20 stories · Sep 01

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Dropbox notified users of unauthorized account access between August 4 and August 21, 2026, stemming from a vulnerability in its single sign-on (SSO) integration with Lenovo IDs. Attackers exploited a missing email verification step in Lenovo's process to create rogue Lenovo IDs, which Dropbox then implicitly linked to existing user accounts without further authentication. This incident highlights critical flaws in federated identity management and the need for robust verification during SSO setup.