Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2636+ Articles
163+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Dropbox Accounts Breached Through Lenovo Email Verification Flaw
Dropbox Accounts Breached Through Lenovo Email Verification Flaw
NEWS

Dropbox Accounts Breached Through Lenovo Email Verification Flaw

A flaw in Lenovo's email verification let attackers register fake Lenovo IDs and silently access ~5,000 Dropbox accounts via SSO.

Dylan H.

News Desk

September 2, 2026
3 min read

A Third-Party Identity Flaw, Not a Dropbox Password Leak

Dropbox is notifying a subset of users that an unauthorized party accessed their accounts — not by stealing Dropbox credentials, but by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs tied to victims' email addresses. Because Dropbox trusted Lenovo's identity verification as part of a legacy SSO integration, those fraudulent IDs were enough to unlock the linked Dropbox accounts.


How the Bypass Worked

Dropbox supports "Continue with SSO" sign-in for users who've linked a Lenovo ID to their account. The flaw sat on Lenovo's side of that handshake: its email verification did not adequately confirm that the person registering a new Lenovo ID actually controlled the email address in question. Attackers used this gap to create Lenovo IDs bound to victims' emails, then rode the existing SSO trust relationship straight into their Dropbox accounts — bypassing the need for a Dropbox password entirely.

One affected user described the first sign something was wrong: the Dropbox login page began offering "Continue with SSO" for their email even though they had never created a Lenovo ID.


Scope and Impact

  • ~5,000 Dropbox accounts were compromised between August 4 and August 21, 2026
  • In some cases, attackers viewed and downloaded files from affected accounts
  • Lenovo confirmed the issue traced to "a legacy integration between Lenovo ID and Dropbox, which could be leveraged to improperly authenticate certain Dropbox accounts" — and said ordinary Lenovo customers were not affected by this specific flaw

Response

Dropbox has:

  1. Expired all sessions that were authenticated via Lenovo ID SSO
  2. Required Dropbox password entry even when signing in through a linked Lenovo ID, closing the trust gap that let the bypass work
  3. Coordinated directly with Lenovo on remediation of the underlying verification flaw

Why It Matters

This incident is a textbook case of third-party identity trust risk: Dropbox's own authentication was never broken, but a weakness in a partner's verification flow was enough to grant full account access. Any service offering "Continue with X" SSO inherits the security posture of X's identity verification — and that inheritance rarely gets the same scrutiny as the primary login path. Users who linked accounts to any third-party ID provider should check for unrecognized sessions and confirm a strong, unique password is still set as a fallback.

Related Reading

  • Substack Data Breach Exposes 700K Users
  • Figure Technology ShinyHunters Breach Hits 1 Million
#Dropbox#Lenovo#Data Breach#Account Takeover#SSO#Identity

Related Articles

Critical Keycloak Flaw Lets Attackers Reset Any Account Password Without Authentication

CVE-2026-18963 (CVSS 9.1) in Keycloak allows unauthenticated attackers to bypass email verification and take over any account. Patch to 26.7.2 immediately.

4 min read

CVE-2026-14182: WooCommerce Email Verification Bypass Allows Account Takeover

A CVSS 9.8 type juggling flaw in Customer Email Verification for WooCommerce lets unauthenticated attackers take over any customer account.

5 min read

CVE-2026-11374: ManageEngine SSO Ticket Prediction Enables Unauthenticated Account Takeover

A critical authentication vulnerability in four ManageEngine products allows unauthenticated attackers to predict SSO session tickets and take over...

5 min read
Back to all News