Abstract:
Recently, many Dropbox network disk users received security notifications stating that their accounts were subject to unauthorized access between August 4 and 21, 2026. This security issue was not caused by a hacker attack on Dropbox's infrastructure. The specific cause was a trust vulnerability in Lenovo ID registration and Dropbox SSO login.

You only need to know your email address to take over Dropbox:
According to the attack chain disclosed so far, there is an email verification flaw in the Lenovo ID registration process. The attacker can use the victim's email address to create a Lenovo account, and there is no need to send an email verification code to verify whether the email address is really owned by the registrant.
The problem was then amplified by the Dropbox SSO login mechanism. Dropbox will match existing accounts based on the email identity provided by Lenovo. Therefore, after the attacker logs in with a fake Lenovo ID, he can directly gain complete control of the corresponding Dropbox account without the need for account passwords and other verifications.
What’s more serious is that the victim did not even need to register a Lenovo ID or bind a Dropbox account before. Dropbox has a long-term cloud storage cooperation with Lenovo, and Lenovo users can purchase and use Dropbox through related services.
Dropbox has forced a session logout and modified the login process:
Dropbox has logged out all sessions established through Lenovo ID after investigation, and has also disassociated the affected accounts from Lenovo ID. If users want to continue accessing through Lenovo ID, they now need to enter their Dropbox account password for verification and can no longer log in directly.
The audit found that some accounts were accessed by hackers during the attack window, but Dropbox said that the current logs found no evidence that user files were viewed or downloaded. In addition, Lenovo has not yet disclosed this incident in a security bulletin.
Comments