Hackers breach 5,000 Dropbox accounts using only victims’ email addresses
Attackers used victims’ emails to create new Lenovo IDs, bypassing password sign-ins to gain access to Dropbox accounts.

Image by Cybernews
- Hackers abused a Lenovo login flaw to access to thousands of Dropbox accounts using victims’ email addresses.
- Dropbox says the issue lasted from August 4 to August 21 and affected at least 5,000 account users.
- Dropbox says it found about one-third of users’ files were viewed or downloaded.
- Dropbox advises affected users to change Dropbox and email passwords and enable two-step verification.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Dropbox begins notifying an unknown number of users this week that hackers gained “unauthorized access” to their accounts – exploiting a flaw in its Lenovo third-party authentication system and using only their email addresses.
The breach, which Dropbox said took place between August 4th and August 21st, involved hackers creating a Lenovo ID using just the victim’s email address and then associating it with the victim's Dropbox account.
Dropbox, in a statement on Tuesday, says about 5,000 accounts were impacted. Most of the accounts that were accessed did not have their two-factor authentication enabled, they said.
“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs,” Dropbox stated in a letter sent to victims and posted on X, explaining how the breach took place.
The now-patched bug simply allowed the attackers to log into the victim’s account using the newly created ID – gaining full access without needing a password.
What’s more, Dropbox said the victims did not necessarily need to have a pre-existing Lenovo ID for the hackers to sign in to their accounts.
Cybernews reached out to Dropbox for comment but did not receive a response before publication.
Was Dropbox user data accessed?
According to a research report by The CyberSec Guru published Tuesday, Lenovo’s authentication flaw let attackers register Lenovo IDs using any email address without verifying who controlled those inboxes.
Dropbox matched the email claim to an existing account and granted a session.The CyberSec Guru said.
The attacker never broke cryptography, phished a password or touched Dropbox’s storage layer,
Dropbox says after containing the issue and launching an investigation, about one-third of the 5,000 accounts compromised show evidence that files were viewed or downloaded.
Despite Dropbox closing the attack window by August 21st, many users have taken to social media to complain that the company waited nearly a week before first alerting customers.
Others argue that logs alone can’t determine whether documents stored on the platform have been accessed.
“Some affected users had years-old tax documents stored in Dropbox, meaning Social Security numbers and financial records sat inside the compromise window regardless of what current logs show,” The CyberSec Guru says.
“Dropbox is perma-banned from my life and anyone who asks me for advice. Unbelievable," one Dropbox user wrote after receiving their own breach notification letter.
Dropbox users raised the alarm
Dropbox apparently discovered the issue after users began reporting receiving “new sign-in” alerts from Dropbox in “mid-August.”
The report says at least one user noticed a “'Continue with SSO' option for an email address that had never been linked to a Lenovo ID."
Some affected users reported rogue Lenovo profiles created under throwaway names, including one false account registered as “John Madden.”
In that case, the account owner, security researcher Yoni Levy, said he was able to take over and deactivate the rogue Lenovo account using the normal password-reset process.
The reset link was sent directly to his actual email inbox.
Besides new Dropbox sign-in alerts – with one traced just outside Dublin, Ireland – other users reported receiving Lenovo verification codes they never requested.
Dropbox recommended actions
In the letter, Dropbox said it took several measures to secure affected user accounts.
The company says it “promptly expired all sessions logged in through Lenovo IDs,” and “severed any link between Lenovo and your Dropbox account.”
Dropbox also stressed that, moving forward, users must enter their Dropbox password before logging in through a Lenovo ID.
“No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password,” it said. The company also urged affected account holders to take the following precautions to help protect their Dropbox accounts, including if their passwords are potentially compromised.
- Change your Dropbox account password.
- Change the password for your email account.
- Enable two-step verification
“Protecting your account and information is extremely important to us,” Dropbox said, providing an email for those with further questions.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.