Dropbox has informed around 5,000 users that their accounts were compromised through a vulnerability associated with a legacy integration that permitted access via Lenovo IDs. The company indicated that attackers exploited an issue in Lenovo’s email verification process, enabling them to register Lenovo IDs using the email addresses of Dropbox users and subsequently gain access to their accounts.
Details of the Breach
The breach occurred between August 4 and August 21, 2026. Dropbox confirmed that attackers accessed files belonging to fewer than a third of the affected users. Notably, none of the compromised accounts had two-factor authentication (2FA) enabled, which could have provided an additional layer of security.
Response from Dropbox
Upon discovering the breach, Dropbox took immediate action by expiring all sessions linked to Lenovo IDs and severing any connections between the affected accounts and Lenovo. In their communication to users, Dropbox advised them to change their Dropbox and personal email passwords and to enable 2FA to enhance their account security.
Lenovo’s Position
Lenovo has stated that its customers are not affected by this incident and that it is continuing its investigation into the matter. The company did not provide further details regarding the nature of the integration or why it allowed access without requiring a Dropbox password.
Implications for Users
This incident underscores the importance of using strong security measures, such as 2FA, to protect online accounts. Users affected by this breach should take the recommended steps to secure their accounts and remain vigilant for any suspicious activity.
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








