Dropbox says an unauthorized party accesses some users’ accounts by exploiting a legacy integration between Lenovo ID and Dropbox. According to the reports, an attacker registers a Lenovo ID using a victim’s email address and then uses that Lenovo login to sign into the victim’s existing Dropbox account without needing the victim’s password.
Dropbox estimates that about 5,000 accounts are compromised. The activity occurs over a defined window, reported as between August 4 and 21. Multiple outlets describe the underlying issue as a weakness in Lenovo’s email verification process, which does not properly verify that the person controlling the email address is the account owner. The outlets collectively frame the incident as an authentication flaw tied to how the two services interact, rather than a breach of Dropbox passwords.
While all sources agree on the basic method and scale, they differ slightly in how they describe the flaw—some emphasize the Lenovo email verification step used to create fraudulent IDs, while others stress the broader authentication weakness enabling passwordless access.