Dropbox notified approximately 5,000 users of potential unauthorized file access due to a Lenovo ID authentication flaw. Attackers exploited a vulnerability where Dropbox trusted unverified Lenovo emails, allowing them to register any email as a Lenovo ID and directly access Dropbox accounts. Dropbox has disconnected all Lenovo ID integrations; affected users were primarily those without two-factor authentication enabled, with actual file access occurring in roughly 1 in 3 compromised accounts.
← Back to all articles