Skip to main content

Dropbox breach seemingly caused by egregious authentication failure

Multiple Dropbox users have been emailed by the cloud storage company to advise them that a security breach saw unauthorised access to their account.

The root cause appears to be a lack of authentication by Dropbox when attackers created a single sign-on option through a third-party company …

Developer Yoni Levy posted a copy of the email he received on X.

We are writing to let you know that we’ve observed unauthorized access to your Dropbox account between August 4 and August 21, 2026. While our logs show no evidence that your files were viewed or downloaded, we want to share with you what happened, what we are doing about it, and what additional steps you can take.

Other Dropbox users reported receiving the same email in which the company said it resulted from a problem with a single sign-on (SSO) option using Lenovo IDs.

Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.

However, while Dropbox claims the flaw was in Lenovo’s email verification process, the bigger issue appears to be that Dropbox itself did not require users to use their existing login to verify the new SSO, as The CyberSec Guru reports.

  1. Recon/selection: The attacker compiles target email addresses (breach corpora, LinkedIn, customer lists — email addresses are effectively public data).
  2. Rogue IdP enrollment: The attacker registers a Lenovo ID as victim@example.com. No inbox access is needed because Lenovo’s verification step is missing or bypassable. The display name is set to something disposable — one victim who reclaimed the rogue account found the name “John Madden,” the late NFL broadcaster, a strong tell of bulk, low-effort registration.
  3. Federated sign-in: The attacker clicks “Continue with Lenovo” on Dropbox. Lenovo’s authorization server issues a token whose email claim matches the victim’s Dropbox account.
  4. Implicit account linking: Dropbox resolves the email claim to the existing account and mints a session. No password prompt, no step-up, no “link this new identity?” consent. From Dropbox’s perspective, a trusted IdP had already vouched for the address.

9to5Mac’s Take

While there was certainly a failure to verify email addresses at the Lenovo end, it would not have done any harm if Dropbox had authenticated the linked ID before it could be used to sign in. Failing to do so is an egregious fault.

The company has now fixed the flaw and expired all sessions previously ‘authenticated’ through a Lenovo ID.

Photo by Shubham Dhage on Unsplash

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Ben Lovejoy Ben Lovejoy

Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He’s known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!


Ben Lovejoy's favorite gear