Dropbox Breach Exposes Identity Flaw in Legacy Lenovo Login Integration
- 12 minutes ago
- 2 min read
A weakness in an old authentication connection between Dropbox and Lenovo allowed an attacker to enter roughly 5,000 Dropbox accounts without obtaining their passwords, according to company notifications.
The compromise targeted Lenovo’s email verification process. An unauthorized party could allegedly create a Lenovo ID using another person’s email address, then present that identity to Dropbox as proof that the attacker controlled the corresponding account.
Dropbox accepted the authentication because Lenovo Identity Provider Services formed part of its external login infrastructure. Even people who had never intentionally created a Lenovo account were potentially exposed.
“While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address,” Dropbox told affected users.
The incident highlights a dangerous weakness in federated identity systems. A platform may have strong password protections and multifactor authentication, but those defenses can be bypassed if a connected identity provider incorrectly verifies who owns an email address.
Attackers accessed the affected Dropbox accounts between August 4 and August 21. Reuters reported that files were viewed or downloaded from some accounts.
Several users said they noticed unfamiliar sign-ins before receiving formal breach notifications. Changing a Dropbox password or enabling two-factor authentication may not have been enough to stop the original attack because the unauthorized access relied on a trusted external login path rather than stolen Dropbox credentials.
Lenovo attributed the exposure to a legacy Dropbox integration and said its own customer accounts were not compromised. The companies disabled the vulnerable pathway after discovering the problem.
Dropbox invalidated sessions created through Lenovo IDs and now requires users attempting to authenticate with a Lenovo identity to also provide their Dropbox password.
Justin Beals, CEO and founder of compliance automation company Strike Graph, said the response was fast but warned that the underlying risk extends beyond these two companies.
“Dropbox moved fast once this surfaced. Identifying the exact integration, cutting the session access, and reporting to regulators is the right playbook, and they deserve credit for the speed of the response. But the root cause here is the part worth sitting with: this wasn't a break-in. It was a trusted integration between two vendors that had been quietly operating for who knows how long, with a gap, in this case no enforced two-factor authentication, that nobody flagged until attackers found it.”
The Dropbox breach offers a broader warning for companies using single sign-on and federated authentication. Every trusted identity connection can become an alternate route into sensitive systems. Security teams should continuously inventory and test those pathways, particularly older integrations that may predate modern verification and multifactor authentication requirements.


