AI Weekly Malaysia

Back to items Summaries

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

ID
20728
Status
summarized
Published
02 Sep 2026, 10:25 PM
Fetched
02 Sep 2026, 11:23 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
6.0
Created
02 Sep 2026, 11:25 PM
Tags
Audience
developerssaas_founders

What happened

Attackers compromised around 5,000 Dropbox accounts by abusing a legacy Lenovo login integration: a flaw in Lenovo's email verification let them register Lenovo IDs using victims' email addresses and access the corresponding Dropbox storage without a Dropbox password. The compromise ran from August 4 to 21; Dropbox has since expired all Lenovo-ID sessions and severed the integration, and confirmed none of the affected accounts had 2FA enabled.

Why it matters

If you ship or maintain federated login / SSO integrations, audit whether any legacy third-party identity provider can grant access to your app without your own password or 2FA gate — this incident shows that a weak email-verification step on the partner side can bypass your account security entirely. Also a concrete prompt to enforce 2FA for your own users, since every compromised account here lacked it.

Discussion angle

How do you inventory and deprecate legacy identity integrations before they become an attack surface, and what minimum verification should you require on your side even when trusting a partner IdP?

Top