VMTech
Discuss a project

Dropbox Links August Account Compromise to Legacy Lenovo ID Integration

Dropbox Links August Account Compromise to Legacy Lenovo ID Integration

About 5,000 Dropbox accounts affected

Dropbox has disclosed that about 5,000 accounts were compromised in August 2026, enabling threat actors to view and download content stored on its cloud-storage platform. The affected accounts were linked to Lenovo ID and did not have two-factor authentication enabled.

Dropbox told Reuters that it identified unauthorised access affecting accounts authenticated through Lenovo ID. The company said it terminated all sessions that had been authenticated through that identity service.

Lenovo said the issue involved a legacy integration between Lenovo ID and Dropbox. In Lenovo’s description, the connection could be used to improperly authenticate certain Dropbox accounts.

Access paths extend beyond passwords

The disclosure illustrates a recurring identity-security problem: an account can remain reachable through an older sign-in relationship even when organisations focus their controls on passwords. The immediate consequence in this case was access to files held in the affected Dropbox accounts.

Dropbox’s response centred on invalidating the sessions created through Lenovo ID. That action matters because active sessions can preserve access after a user changes credentials, while a connected identity service can become an alternative authentication path.

Two-factor authentication was not enabled on the affected accounts. The incident therefore combines an old integration with a weaker sign-in setting, rather than describing a compromise of Dropbox’s core storage infrastructure.

A practical review for businesses

Security teams should inventory the identity providers connected to important business applications and determine whether each connection is still required. They should also identify accounts without multi-factor authentication, especially where legacy federation or partner integrations remain available.

When investigating suspected account misuse, resetting a password should not be the only recovery action. Teams can also review and end active sessions, remove unrecognised application permissions, and check whether remote-access tools have been authorised. The business implication is clear: reducing obsolete access paths and validating existing connections can limit exposure before another sign-in route is abused.

#cybersecurity#identitysecurity#dropbox#mfasecurity
Open analytics
On the site 0 views
min read 3 03.09.2026
Instagram

Dropbox Links August Account Compromise to Legacy Lenovo ID Integration

Open the post on Instagram ↗