A Third-Party Identity Flaw, Not a Dropbox Password Leak
Dropbox is notifying a subset of users that an unauthorized party accessed their accounts — not by stealing Dropbox credentials, but by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs tied to victims' email addresses. Because Dropbox trusted Lenovo's identity verification as part of a legacy SSO integration, those fraudulent IDs were enough to unlock the linked Dropbox accounts.
How the Bypass Worked
Dropbox supports "Continue with SSO" sign-in for users who've linked a Lenovo ID to their account. The flaw sat on Lenovo's side of that handshake: its email verification did not adequately confirm that the person registering a new Lenovo ID actually controlled the email address in question. Attackers used this gap to create Lenovo IDs bound to victims' emails, then rode the existing SSO trust relationship straight into their Dropbox accounts — bypassing the need for a Dropbox password entirely.
One affected user described the first sign something was wrong: the Dropbox login page began offering "Continue with SSO" for their email even though they had never created a Lenovo ID.
Scope and Impact
- ~5,000 Dropbox accounts were compromised between August 4 and August 21, 2026
- In some cases, attackers viewed and downloaded files from affected accounts
- Lenovo confirmed the issue traced to "a legacy integration between Lenovo ID and Dropbox, which could be leveraged to improperly authenticate certain Dropbox accounts" — and said ordinary Lenovo customers were not affected by this specific flaw
Response
Dropbox has:
- Expired all sessions that were authenticated via Lenovo ID SSO
- Required Dropbox password entry even when signing in through a linked Lenovo ID, closing the trust gap that let the bypass work
- Coordinated directly with Lenovo on remediation of the underlying verification flaw
Why It Matters
This incident is a textbook case of third-party identity trust risk: Dropbox's own authentication was never broken, but a weakness in a partner's verification flow was enough to grant full account access. Any service offering "Continue with X" SSO inherits the security posture of X's identity verification — and that inheritance rarely gets the same scrutiny as the primary login path. Users who linked accounts to any third-party ID provider should check for unrecognized sessions and confirm a strong, unique password is still set as a fallback.