A developer named Yoni Levy posted a screenshot this week of a security email from Dropbox hack warning him that a new browser had logged into his account from Canary Wharf, London, at 6:06 a.m. He had never owned a Lenovo product and had never been to the United Kingdom. Levy was one of roughly 5,000 people caught up in a Dropbox hack that did not require stealing a single password, just knowledge of a victim’s email address.
What Happened: A Lenovo Login Flaw Let Attackers Into Dropbox
Dropbox confirmed on September 1, 2026, that hackers accessed roughly 5,000 user accounts between August 4 and August 21. Notably, Dropbox’s own servers were never breached. The problem traced back to a legacy integration that let Dropbox users sign in with a verified Lenovo ID instead of a Dropbox password. A flaw in Lenovo’s own email verification process let an attacker register a brand-new Lenovo ID using someone else’s existing email address, with no proof that the person actually owned that email or had ever used Lenovo’s services before.
Dropbox treated that freshly created, fraudulent Lenovo ID as a legitimate, verified login for the matching Dropbox account, no password required. Dropbox said fewer than a third of the affected accounts actually had files viewed or downloaded, but every one of the roughly 5,000 accounts was accessible to whoever ran the attack.
How the Dropbox Hack Actually Worked
Services often let you log in through a trusted third party instead of creating a new password, known as single sign-on. Dropbox’s Lenovo integration worked this way: if Lenovo says a login is verified, Dropbox accepts it as proof of identity. That setup only holds up if Lenovo’s own verification is solid. It wasn’t. An attacker could sign up for a new Lenovo ID using a target’s email address without confirming they actually controlled that inbox, then use that fabricated identity to walk straight into the matching Dropbox account.
The victim’s actual Dropbox password was never touched, guessed, or leaked. It simply became irrelevant, because the attacker came in through a side door Dropbox had agreed to trust.
The One Thing That Would Have Stopped Every Case
Here is the detail worth remembering above everything else in this story: every single one of the roughly 5,000 compromised accounts had two-factor authentication turned off. Dropbox users who had enabled two-step verification were untouched by this entire incident, regardless of the Lenovo flaw. The fraudulent login could get past a missing password, but it could not get past a second verification step tied to the real account owner’s phone or authenticator app.
What Dropbox Has Done Since
Dropbox said it immediately expired every session that had logged in through a Lenovo ID and severed the login link between the two platforms entirely. It has also changed the integration so that, going forward, a Dropbox password is required even when signing in through a Lenovo ID, closing the specific gap that made this possible. Dropbox notified affected users directly and reported the incident to data protection regulators. Lenovo, for its part, said its own core customer accounts were not affected, since the flaw sat specifically in the identity-verification step feeding into the Dropbox integration.
What You Should Do Right Now
- Turn on two-factor authentication for Dropbox and any other cloud storage service today. This single step would have stopped every account in this incident.
- Review which third-party accounts are linked to your cloud storage and email. Remove any single sign-on connections you don’t actively use or recognize.
- Check your account’s recent login activity for locations or devices you don’t recognize, the same signal that first tipped off affected users in this case.
- Change your Dropbox password as a precaution if you’re unsure whether your account was among those affected, even though the vulnerability itself has been closed.
This incident fits a pattern worth watching closely: attacks that succeed without ever touching a password at all. Our earlier piece on session hijacking malware and the warning signs to watch for covers a related risk, where the login itself gets stolen rather than guessed. For the full technical detail on this incident, TechRadar’s original report is a solid primary source.
Dropbox hack-Final Thoughts
The Dropbox hack is a reminder that the weakest link in your account security isn’t always your own password, sometimes it’s a trust relationship between two companies you never thought to question. You can’t audit every third-party integration a service you use has quietly built over the years. You can turn on two-factor authentication, and in this case, that one step was the difference between five thousand compromised accounts and zero.