Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
- ID
- 20728
- Status
- summarized
- Published
- 02 Sep 2026, 10:25 PM
- Fetched
- 02 Sep 2026, 11:23 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.0
- Created
- 02 Sep 2026, 11:25 PM
- Tags
- Audience
- developerssaas_founders
What happened
Attackers compromised around 5,000 Dropbox accounts by abusing a legacy Lenovo login integration: a flaw in Lenovo's email verification let them register Lenovo IDs using victims' email addresses and access the corresponding Dropbox storage without a Dropbox password. The compromise ran from August 4 to 21; Dropbox has since expired all Lenovo-ID sessions and severed the integration, and confirmed none of the affected accounts had 2FA enabled.
Why it matters
If you ship or maintain federated login / SSO integrations, audit whether any legacy third-party identity provider can grant access to your app without your own password or 2FA gate — this incident shows that a weak email-verification step on the partner side can bypass your account security entirely. Also a concrete prompt to enforce 2FA for your own users, since every compromised account here lacked it.
Discussion angle
How do you inventory and deprecate legacy identity integrations before they become an attack surface, and what minimum verification should you require on your side even when trusting a partner IdP?