NewsLayer.com
NewsLayer PulseLIVEBTC$77,118-2.33%ETH$2,413-2.63%SOL$99.45-4.04%XRP$1.35-2.77%DOGE$0.0816-2.13%ADA$0.1956-1.85%Total Cap$2.72T-2.28%Layer Index48 Neutral

Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw

Attackers reportedly registered Lenovo IDs using victims’ email addresses, allowing them to sign into existing Dropbox accounts without their passwords.

Jason Nelson

Publisher Decrypt

Sep 1, 2026 at 8:01 PM UTC · 2 min de lecture

Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw
Image via Decrypt
Traduction…

In brief

  • Dropbox notified users of unauthorized account access between August 4 and August 21 after attackers reportedly exploited a Lenovo ID authentication issue.
  • One affected user received an alert showing a login from near Canary Wharf in London using Chrome on Windows.
  • Dropbox said it found no evidence that files were viewed or downloaded and has since changed how Lenovo IDs can access accounts.

Multiple Dropbox users were notified that unauthorized parties accessed their accounts through an authentication flaw involving Lenovo ID.

The incident appears to have exploited the way Dropbox handled single sign-on, or SSO, through Lenovo IDs. Dropbox said an issue with Lenovo’s email verification process allowed unauthorized parties to register Lenovo IDs using other people’s email addresses and then use those identities to access the Dropbox accounts associated with the same addresses.

Myriad: Tesla highs in September? Click to make your prediction.

In a letter to affected users, Dropbox said accounts were accessed without authorization between August 4 and August 21, 2026, though the company said logs showed no evidence that files were viewed or downloaded.

“We recently identified unauthorized access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled,” a Dropbox spokesperson told Decrypt. “Our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using another person’s email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”

Article Intelligence

Related Coverage

View all related

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium