Independent Reviews
Abstract glass data vault fractured by a security breach
Data Breach Published 3 Sept 2026 5 min read1 source

Dropbox Accounts Accessed Through Lenovo ID Verification Flaw

Dropbox says an attacker registered fraudulent Lenovo IDs with other people's email addresses and used the linked sign-in route to enter some Dropbox accounts without their Dropbox passwords. Dropbox and Lenovo say they have mitigated the legacy integration issue.

By VPN Rocks Editorial Team

The short version

What you need to know

  • BleepingComputer reports that a flaw in a legacy Lenovo ID integration let an attacker register a Lenovo identity with somebody else's email address and use it to authenticate to the matching Dropbox account.
  • Dropbox said the affected access occurred between 4 and 21 August. It expired Lenovo-authenticated sessions and now requires the Dropbox password when Lenovo ID is used to sign in.
  • Recipients of a Dropbox notice should verify it through the official app or a typed address, review sessions and file activity, secure the account and assess any exposed files. A VPN cannot repair a linked-login flaw or withdraw downloaded cloud data.

How did the linked-login route work?

BleepingComputer says Dropbox notified affected users that an issue in Lenovo's email-verification process allowed an unauthorised party to create a Lenovo ID using their email address. The attacker could then use that identity to enter the Dropbox account associated with the same address without knowing its Dropbox password.

The report says some recipients did not already have Lenovo accounts. The weak point was the trust relationship between identity systems: Dropbox accepted Lenovo's assertion that the person controlled the email address without requiring confirmation through the existing Dropbox login.

What Dropbox and Lenovo changed

Dropbox told affected users that the unauthorised access occurred between 4 and 21 August. According to BleepingComputer, Dropbox expired all sessions authenticated through Lenovo IDs and changed the flow so a user must enter the Dropbox account password when signing in with Lenovo ID.

Lenovo described the cause to BleepingComputer as a legacy integration that could be used to authenticate improperly to certain Dropbox accounts. It said both companies worked together to mitigate the risk and that Lenovo customers were not affected by the issue. The investigation was continuing when the report was published.

What notified users should do now

Open Dropbox from its official app or by typing the address rather than following a message link. Review security alerts, signed-in devices, web sessions, connected apps, sharing activity and recently changed or downloaded files. Sign out unfamiliar sessions, remove connections you do not recognise, set a unique password and enable multi-factor authentication.

Account security is only one part of the response. If another person viewed or downloaded files, changing the password will not retrieve those copies. Check what the account contained, rotate exposed credentials or recovery codes, tell affected people or organisations where appropriate, and follow Dropbox's direct notice for incident-specific steps.

Where a VPN helps — and where it does not

A reputable VPN can encrypt supported network traffic between a device and the VPN provider, which is useful against local-network observation on untrusted Wi-Fi. It does not decide whether a linked identity provider has correctly verified an email address.

A VPN therefore cannot prevent this authentication logic flaw, invalidate a fraudulent Lenovo ID, eject an existing cloud session or recover downloaded files. Strong identity linking, session revocation, account review, multi-factor authentication and careful handling of exposed file contents are the relevant controls.

VPN Rocks view

A login can be only as strong as every identity service trusted to open it. Services should require proof through the existing account before attaching a new external identity, especially where the user never established that identity-provider relationship themselves.

Users should treat unexpected single-sign-on options and unfamiliar authentication alerts as meaningful signals. Cloud accounts often contain records that remain sensitive long after upload, so reviewing stored data and unnecessary sharing is as important as resetting access.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps