Lenovo Verification Flaw Exposes 5,000 Dropbox Accounts to Unauthorized Access
Threat actors exploited a loophole in Lenovo's email verification mechanism to access linked Dropbox cloud accounts without passwords.

A security flaw in Lenovo’s identity verification mechanism allowed cybercriminals to breach approximately 5,000 Dropbox user accounts using only target email addresses, as first reported by TechRadar Pro. The incident highlights vulnerabilities associated with third-party authentication integrations when single sign-on pathways lack robust verification protocols.
Dropbox recently began issuing official data breach notification emails to affected customers, detailing how the unauthorized access occurred. According to the company, Dropbox maintains a partnership with PC manufacturer Lenovo as an identity provider, enabling users to sign into their cloud storage accounts utilizing verified Lenovo IDs.
However, an investigation revealed a flaw within Lenovo’s email confirmation workflow that allowed unauthorized parties to establish Lenovo IDs using third-party email addresses without verification. The threat actors then leveraged these newly created Lenovo IDs to gain entry into the corresponding Dropbox accounts linked to those target email addresses.
The unauthorized access occurred over a seventeen-day period between August 4 and August 21. Dropbox reported that the vast majority of the compromised accounts did not have multi-factor authentication enabled. Furthermore, forensic analysis indicated that in approximately one-third of the impacted accounts, unauthorized actors successfully viewed or downloaded stored files.
In response to the security incident, Dropbox implemented several containment steps to secure affected user accounts. The cloud storage vendor immediately terminated all active user sessions initiated through Lenovo IDs and severed existing account connections between the two platforms. Additionally, Dropbox altered its authentication requirements, making a valid Dropbox password mandatory whenever attempting to log in via a Lenovo ID pathway.
Despite closing the vector, Dropbox advised affected account holders to update their account passwords, turn on two-step verification, and change credentials for their associated email accounts to mitigate any lingering security risks.
Security experts noted that the incident underscores systemic risks in identity management and user authentication practices. Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, emphasized that every compromised account lacked multi-factor authentication, describing unmonitored third-party authentication channels paired with single-factor accounts as an open vulnerability.
Patel added that organizations and individual users should routinely review third-party service connections, noting that OAuth permissions, single sign-on integrations, and secondary login credentials frequently persist long after their operational need has expired.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



