Dropbox Data Breach

48 points by hmate9 2 days ago

I received a security notice from Dropbox today saying that my account was accessed without authorization between August 4 and August 21, 2026, and that Dropbox believes files in the account were viewed or downloaded.

According to the email, Dropbox uses Lenovo as an identity provider, allowing users to authenticate to Dropbox with a verified Lenovo ID.

Dropbox says:

an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.

So, as I understand it, the attack path was roughly:

1. Attacker registers a Lenovo ID using the victim’s email address. 2. Lenovo incorrectly treats the email address as verified. 3. Dropbox trusts the Lenovo identity. 4. Attacker gets access to the Dropbox account associated with that email address.

Dropbox says it has since expired all sessions authenticated through Lenovo ID and removed the Lenovo link from my account. It also says Lenovo authentication can no longer be used for the account without first entering the Dropbox password.

I’ve searched for a public disclosure from Dropbox or Lenovo and haven’t found one yet.

Has anyone else received the same notice, or seen any public information about this vulnerability?

I’m particularly interested in knowing how broadly the Lenovo ID login mechanism was available and how many Dropbox accounts may have been affected.

xaphod 2 days ago

I got this same email about an hour ago.

About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.

One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.

phendrenad2 2 days ago

This is such a colossal fuckup, they need to do a full postmortem and heads need to roll. This is a "you had one job" situation. This is all hands on deck. This is potentially company-ending. If this happened at Github it would be huge news.

  • djanogo 2 days ago

    Agree, after over a decade I am about to delete all my files and close the account.

    The culture in the company would have to be fu*ked to allow this type of breach. There is no official Dropbox public letter or CEO apology post yet, seems like problem starts at the top with new CEO.

  • haute_cuisine 2 days ago

    Hardware shops can't do software, software shops can't do hardware. Just never put any hardware company in secure sensitive software related flows.

ThePhysicist 2 days ago

Damn, big security fuckup by Dropbox, how can they portray that as an issue with Lenovo's e-mail verification process? You should never allow linking of an existing account with a new login method without first confirming that the user is able to sign in with an existing method first! Everyone knows this allows easy account takeovers otherwise, that's such a trivial attack vector, truly a scenario you could pose to a junior security engineer in an interview.

aitchnyu 2 days ago

What is Lenovo doing here? Were they bundling Dropbox with their devices?