Cloud storage service Dropbox informed about 5,000 users this week that their accounts were accessed by hackers between August 4 and August 21, 2026, due to a dormant Lenovo ID sign-in integration that allowed the attackers direct access without the use of a password.
The users at risk were Dropbox users who stored files in the cloud storage app and never initiated multi-factor authentication.
Dropbox login accessed without a password
The loophole that granted the attackers access was the integration connection between Lenovo ID and Dropbox, and not any of the products particularly. According to TheNextWeb, anyone could register a Lenovo ID against an email address that was not theirs, because Lenovo’s setup never confirmed the address belonged to them. Dropbox, however, saw the Lenovo token as a proof of identity and then allowed access to the matching account.
The security writer The CyberSec Guru, cited by 9to5Mac, described the timeline of events. Bad actors and hackers collect public email addresses, after which they enroll a Lenovo ID under a victim’s address. The hackers then used the “Continue with Lenovo” option on Dropbox, handing them access to a live session that does not require a password prompt and subsequently direct access to the Dropbox account.
One user who reclaimed a previously accessed rogue account found it carried the display name “John Madden,” which 9to5Mac claims is a sign of bulk registrations.
What was lost in the attack?
Files were viewed or downloaded on less than a third of the approximately 5,000 accounts opened over the period of this attack. This means there were about 1,500 accounts where material was actually taken, according to 9to5Mac’s update, and around 3,500 where there were no traces of files being touched. It remains unclear if the intruders were after specific documents or simply swept through accounts automatically.
The hackers were said to have viewed and downloaded material on a smaller share of accounts, and spokesperson Tim Rathschmidt stated that none of the breached accounts used multi-factor authentication. Rathschmidt also added that Dropbox does not expect this incident to be a hit on its business.
Dropbox switches off Lenovo ID integration
Upon finding out about the issue, Dropbox killed every session that had been authenticated through a Lenovo ID, switched off the integration, and now demands a native Dropbox password before any account can be accessed.
Lenovo traced the hack to a “legacy integration” that it claimed could be used to “improperly authenticate certain Dropbox accounts.” The company said its own users remained completely unaffected, and confirmed that its investigation was still open.
The breach surfaced via a later investigation and was not picked up by the monitoring systems of both companies.
Multi-factor authentication would have blocked the attack, because the loophole took advantage of the need for no password using the Lenovo ID integration, granting access if there was no second check for certainty.
If you’re reading this, you’re already ahead. Stay there with our newsletter.
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
