Hackers Breach 5,000 Dropbox Accounts via Lenovo Vulnerability
Dropbox reported a breach of 5,000 user accounts after hackers exploited a legacy email verification vulnerability in Lenovo's systems to bypass authentication.
Hackers compromised approximately 5,000 Dropbox Inc. accounts between August 4 and August 21, 2026. The attackers exploited a vulnerability in the Lenovo Group Ltd. email verification process, which Lenovo described as a legacy integration between the two services.
The attackers registered Lenovo IDs using the email addresses of Dropbox users who had not previously created such accounts. They then used these IDs to bypass authentication on Dropbox accounts that lacked multifactor protection. Dropbox reported that files were viewed and downloaded from less than a third of the affected accounts.
Dropbox has notified regulators and affected users, stating it does not expect the breach to have a material impact on its business. Following the announcement, Dropbox shares fell as much as 6.6% in postmarket trading. Both companies worked together to mitigate the risk after the vulnerability was identified.