Cloud storage service Dropbox informed about 5,000 users this week that their accounts were accessed by hackers between August 4 and August 21, 2026, due to a dormant Lenovo ID sign-in integration that allowed the attackers direct access without the use of a password.
The users at risk were Dropbox users who stored files in the cloud storage app and never initiated multi-factor authentication.
Dropbox login accessed without a password
The loophole that granted the attackers access was the integration connection between Lenovo ID and Dropbox, and not any of the products particularly. According to TheNextWeb, anyone could register a Lenovo ID against an email address that was not theirs, because Lenovoβs setup never confirmed the address belonged to them. Dropbox, however, saw the Lenovo token as a proof of identity and then allowed access to the matching account.
The security writer The CyberSec Guru, cited by 9to5Mac, described the timeline of events. Bad actors and hackers collect public email addresses, after which they enroll a Lenovo ID under a victimβs address. The hackers then used the βContinue with Lenovoβ option on Dropbox, handing them access to a live session that does not require a password prompt and subsequently direct access to the Dropbox account.
One user who reclaimed a previously accessed rogue account found it carried the display name βJohn Madden,β which 9to5Mac claims is a sign of bulk registrations.
What was lost in the attack?
Files were viewed or downloaded on less than a third of the approximately 5,000 accounts opened over the period of this attack. This means there were about 1,500 accounts where material was actually taken, according to 9to5Macβs update, and around 3,500 where there were no traces of files being touched. It remains unclear if the intruders were after specific documents or simply swept through accounts automatically.
The hackers were said to have viewed and downloaded material on a smaller share of accounts, and spokesperson Tim Rathschmidt stated that none of the breached accounts used multi-factor authentication. Rathschmidt also added that Dropbox does not expect this incident to be a hit on its business.
Dropbox switches off Lenovo ID integration
Upon finding out about the issue, Dropbox killed every session that had been authenticated through a Lenovo ID, switched off the integration, and now demands a native Dropbox password before any account can be accessed.
Lenovo traced the hack to a βlegacy integrationβ that it claimed could be used to βimproperly authenticate certain Dropbox accounts.β The company said its own users remained completely unaffected, and confirmed that its investigation was still open.
The breach surfaced via a later investigation and was not picked up by the monitoring systems of both companies.
Multi-factor authentication would have blocked the attack, because the loophole took advantage of the need for no password using the Lenovo ID integration, granting access if there was no second check for certainty.
The smartest crypto minds already read our newsletter. Want in? Join them.



















English (US)