Cybersecurity

Lenovo Email Verification Flaw Enabled Access to Approximately 5,000 Dropbox Accounts

Dropbox warned some users of unauthorized access to their accounts after a flaw in Lenovo’s email verification mechanism was exploited to create fake identities. The company said attackers were able to access the accounts between August 4 and 21, while Dropbox imposed additional login measures and revoked sessions associated with Lenovo identities.

2026-09-02
3 min read
6 views
فريق تحرير certi.news
Lenovo Email Verification Flaw Enabled Access to Approximately 5,000 Dropbox Accounts

Dropbox warned users that their accounts had been accessed without authorization after a flaw in Lenovo’s email verification process was exploited. The flaw allowed an attacker to create a Lenovo ID using the victim’s email address, then use that identity to sign in to the Dropbox account associated with the same email address without entering the Dropbox password.

According to information Dropbox sent to affected users, some victims did not have Lenovo accounts at all. However, Dropbox uses Lenovo Identity Provider Services as part of its authentication infrastructure, allowing users to sign in to its accounts using verified Lenovo identities.

How Was the Flaw Exploited?

The linking process between the two services relied on Lenovo confirming that the identity owner controlled the email address. However, the system did not request additional confirmation through the existing login method for the Dropbox account. As a result, an attacker could create a fraudulent Lenovo ID using a Dropbox user’s email address, then use it to access the account associated with that same address.

Dropbox detected access activity between August 4 and 21. Reuters reported that approximately 5,000 accounts were accessed and that the attacker viewed and downloaded content from some accounts. The published information did not specify the volume of data downloaded or the number of users actually affected by file downloads.

Dropbox and Lenovo’s Response

Lenovo said the issue stemmed from an old integration between Lenovo ID and Dropbox that could be exploited to improperly authenticate certain Dropbox accounts. The company added that its teams worked with Dropbox to mitigate the risk as soon as the issue was identified.

For its part, Dropbox revoked all sessions authenticated through Lenovo ID and added a new requirement for users to enter their Dropbox account password when using Lenovo ID authentication. Some users also reported receiving notifications about suspicious logins approximately two weeks earlier, after which they changed their passwords and enabled two-factor authentication.

Why Does This Matter?

The incident reveals a practical risk in single sign-on systems: account security depends not only on the service provider that stores the data, but also on the accuracy of the relationship between the identity provider and the service connected to it. If a service accepts an untrusted confirmation regarding ownership of an email address, a user’s account may be put at risk even without their password being exposed.

The incident also shows that the appearance of a new login option, such as a “Continue with SSO” button for an account whose owner never created a Lenovo identity, may be a sign worth investigating, especially when the user does not remember enabling this integration. However, the source does not establish that every appearance of this option represents a compromise.

Dropbox said the investigation is still ongoing, while stating that Lenovo customers were not affected by the issue. As of the time of publication, the company had not provided additional details in response to inquiries from BleepingComputer. Questions concerning the scope of the files that were downloaded and the exact number of affected accounts remain open pending the release of final findings.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news