Dropbox has alerted users to unauthorized access of their accounts, which occurred between August 4 and August 21. The security incident was reportedly caused by an authentication flaw involving Lenovo ID, the single sign-on service used by some Dropbox users. Attackers exploited an issue with Lenovo's email verification process, allowing them to register Lenovo IDs with email addresses belonging to other individuals. These newly created Lenovo IDs were then used to log into the corresponding Dropbox accounts without needing the user's Dropbox password or access to their email inbox.
Dropbox stated that approximately 5,000 accounts were impacted. The company emphasized that its investigation found no evidence that files were viewed or downloaded for the majority of these accounts. However, less than a third of the affected accounts did have files viewed or downloaded. Dropbox has directly emailed all impacted users and has since modified its authentication procedures related to Lenovo IDs to prevent future exploitation.
One affected user, developer Yoni Levy, shared screenshots of the notification on X, detailing a login to his account via Chrome on Windows from near Canary Wharf, England, on August 18. Levy stated he had no Lenovo account and had never been to the UK.