Hackers Breached 5,000 Dropbox Accounts Using Just an Email Address, No Password Required

Imagine discovering when you wake up that a hacker has gained access to your cloud storage account without ever having to guess or steal your password. Between August 4 and August 21, 2026, this became a reality for about 5,000 Dropbox users. The offender? A vulnerability in Dropbox's interface with Lenovo's identity system, which has since been fixed, allowed hackers to create phony Lenovo IDs using just the victim's email address.
How the Attack Worked
Lenovo and Dropbox collaborate as identity providers, enabling customers to access their Dropbox accounts with valid Lenovo IDs. Lenovo's email verification procedure was flawed, allowing hackers to generate fake Lenovo IDs without any verification. Using the victim's email address, the attackers created a Lenovo ID, linked it to the victim's Dropbox account, and completely circumvented the password. Users were at risk even if they didn't already have a Lenovo ID.
What Was at Risk
Security researcher Yoni Levy found a rogue Lenovo account registered under the name "John Madden" linked to his email, and he was able to take control of it using the standard password-reset procedure because the method was so straightforward. Attackers did not need to phish credentials, crack cryptography, or breach Dropbox's storage layer. All they required was a weak authentication handshake between two reliable systems and an email address.
What Was at Risk
According to Dropbox, there is no indication in its logs that files were viewed or downloaded. Many impacted users are still dubious, though. Some had financial records, Social Security numbers, and tax paperwork from years before kept in their accounts. There was ample opportunity for data exposure over the 18-day attack window, and logs alone cannot verify that documents were not viewed.
The Response and the Delay
In response, Dropbox broke the connection between Lenovo and the impacted accounts and terminated all sessions accessed with Lenovo IDs. Going forward, before using a Lenovo ID to log in, customers will need to input their Dropbox password.
Nonetheless, a lot of people chastised the business for keeping them in the dark for almost a week. Midway through August, a few impacted customers reported getting "new sign-in" warnings from Dropbox, one of which was linked to an IP address close to Dublin.
What You Should Do
Take these actions right away if you use Dropbox:
- Modify your Dropbox password and activate two-step authentication.
- As a precaution, change the password for your email account.
- Examine linked apps and eliminate any strange integrations.
- Keep an eye out for questionable activities in your email and account.
How Bayon Technologies Group Can Help You Stay Safe
Third-party identity integrations are a crucial security blind spot that the Dropbox-Lenovo breach highlights. Through thorough identity security assessments and vendor risk management, we at Bayon Technologies Group assist enterprises in locating and fixing these hidden weaknesses.
We offer:
- Audits of third-party authentication to assess each identity provider's security stance
- Monitoring identity threats to find attempts at illegal access throughout your cloud ecosystem
- MFA enforcement techniques to guarantee multi-factor protection for every account
- Planning for incident response will enable you to respond swiftly to breaches.
Don't let a trusted partnership become your next security incident. Contact Bayon Technologies Group today to build a defense strategy that protects your data—even when your vendors fall short.
‹ Back


