Dropbox confirmed on September 1, 2026 that hackers hijacked roughly 5,000 accounts by exploiting a broken identity check in Lenovo's login system, no stolen password required.
You don't need a stolen password to break into someone's Dropbox account. You just need their email address, and a login system on the other end that doesn't check it carefully enough.
Dropbox confirmed on September 1, 2026 that roughly 5,000 accounts were compromised between August 4 and August 21. The flaw wasn't Dropbox's code. It sat inside Lenovo ID, the single sign-on service Lenovo built so laptop owners could log into partner apps without a separate password. Bloomberg first reported the breach. Reuters and BleepingComputer followed, then The Register added more detail.
The mechanism was almost embarrassingly simple. Anyone could register a Lenovo ID using someone else's email address, because Lenovo's system never actually confirmed that the person signing up owned that inbox. Dropbox, for its part, had long treated a verified Lenovo ID as trustworthy enough to open the matching Dropbox account on its own, no separate password check required.
Put those two facts together and you get an account takeover that skips the part everyone worries about. An attacker didn't need to guess a password, or phish one out of someone. Cracking one wasn't necessary either. They needed a target's email address, and a few minutes to sign up for a Lenovo ID pretending to be them.
More Info