Dropbox breach compromises 5,000 accounts through Lenovo ID loophole
- ID
- 20583
- Status
- summarized
- Published
- 02 Sep 2026, 12:26 PM
- Fetched
- 02 Sep 2026, 12:40 PM
- Provider
- Malay Mail Tech
- Category
- malaysia-tech
- Original URL
- https://www.malaymail.com/news/tech-gadgets/2026/09/02/dropbox-breach-compromises-5000-accounts-through-lenovo-id-loophole/233630
- Source URL
- https://www.malaymail.com/feed/rss/tech-gadgets
Summary
- Score
- 5.5
- Created
- 02 Sep 2026, 12:41 PM
- Tags
- Audience
- developerssaas_founders
What happened
Approximately 5,000 Dropbox accounts were compromised in August after hackers exploited Lenovo's email verification process to create unauthorized Lenovo IDs, gaining access to Dropbox accounts that lacked multi-factor authentication. Dropbox has since severed the integration with Lenovo IDs and reinforced authentication requirements. Lenovo confirmed the issue stemmed from a 'legacy integration' with Dropbox.
Why it matters
If you ship SaaS with third-party identity provider integrations, this is a concrete reminder to audit legacy OAuth/SAML connections and enforce MFA on your side rather than trusting the partner's verification flow. The breach happened specifically because Dropbox accepted Lenovo ID assertions for accounts without MFA—meaning any dormant third-party auth integration you forgot about can become an attack surface.
Discussion angle
What dormant or legacy identity integrations does your current stack still trust, and do you enforce MFA independently of what the identity provider claims to verify?