Dropbox and Lenovo: Dropbox breach seemingly caused by egregious authentication failure

Dropbox and Lenovo: Dropbox breach seemingly caused by egregious authentication failure

Dropbox Security Breach Exposes Flaw in Third-Party SSO Authentication

Dropbox recently notified multiple users of unauthorized access to their accounts between August 4 and August 21, 2026, stemming from a vulnerability in its single sign-on (SSO) integration with Lenovo IDs. While the company confirmed no files were viewed or downloaded, the incident highlights critical gaps in authentication protocols.

The breach occurred when attackers exploited Lenovo’s flawed email verification process to register Lenovo IDs using victims’ email addresses without requiring inbox access. These rogue IDs were then used to log into Dropbox accounts via Lenovo’s SSO, as Dropbox did not require re-authentication for new identity providers. The attack relied on publicly available email addresses (e.g., from breaches or LinkedIn) and bulk registration tactics, with some fake accounts using disposable names like "John Madden."

Security analysts note that while Lenovo’s verification failure enabled the attack, Dropbox’s lack of secondary authentication for new SSO logins was the primary vulnerability. The company has since patched the flaw and invalidated all sessions linked to Lenovo IDs. The incident underscores risks in federated identity systems when trust in third-party providers is not properly validated.

Source: https://9to5mac.com/2026/09/01/dropbox-login-breach-seemingly-caused-by-egregious-authentication-failure/

Dropbox cybersecurity rating report: https://www.rankiteo.com/company/Dropbox

Lenovo cybersecurity rating report: https://www.rankiteo.com/company/lenovo

"id": "DROLEN1788267915",
"linkid": "Dropbox, lenovo",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Multiple users',
                        'industry': 'Cloud Storage',
                        'name': 'Dropbox',
                        'type': 'Company'},
                       {'industry': 'Technology',
                        'name': 'Lenovo',
                        'type': 'Company'}],
 'attack_vector': 'Exploitation of third-party SSO vulnerability',
 'customer_advisories': 'Notified affected users of unauthorized access',
 'data_breach': {'data_exfiltration': 'No',
                 'personally_identifiable_information': 'Email addresses '
                                                        '(publicly available)',
                 'sensitivity_of_data': 'Low (no files viewed/downloaded)',
                 'type_of_data_compromised': 'Account access (no file '
                                             'content)'},
 'date_detected': '2026-08-21',
 'description': 'Dropbox recently notified multiple users of unauthorized '
                'access to their accounts between August 4 and August 21, '
                '2026, stemming from a vulnerability in its single sign-on '
                '(SSO) integration with Lenovo IDs. The breach occurred when '
                'attackers exploited Lenovo’s flawed email verification '
                'process to register Lenovo IDs using victims’ email addresses '
                'without requiring inbox access. These rogue IDs were then '
                'used to log into Dropbox accounts via Lenovo’s SSO, as '
                'Dropbox did not require re-authentication for new identity '
                'providers. The attack relied on publicly available email '
                'addresses and bulk registration tactics.',
 'impact': {'brand_reputation_impact': 'Undermined trust in federated identity '
                                       'systems',
            'data_compromised': 'No files were viewed or downloaded, but '
                                'unauthorized access to accounts occurred',
            'identity_theft_risk': 'Potential risk due to unauthorized account '
                                   'access',
            'systems_affected': 'Dropbox accounts linked to Lenovo SSO'},
 'initial_access_broker': {'entry_point': 'Exploitation of Lenovo’s flawed '
                                          'email verification process'},
 'lessons_learned': 'Critical gaps in authentication protocols for federated '
                    'identity systems, particularly when trust in third-party '
                    'providers is not properly validated.',
 'post_incident_analysis': {'corrective_actions': 'Dropbox patched the SSO '
                                                  'vulnerability and '
                                                  'invalidated affected '
                                                  'sessions',
                            'root_causes': 'Lenovo’s flawed email verification '
                                           'process and Dropbox’s lack of '
                                           'secondary authentication for new '
                                           'SSO logins'},
 'recommendations': 'Implement secondary authentication for new SSO logins and '
                    'ensure third-party identity providers have robust email '
                    'verification processes.',
 'response': {'communication_strategy': 'Notified affected users',
              'containment_measures': 'Invalidated all sessions linked to '
                                      'Lenovo IDs',
              'remediation_measures': 'Patched the SSO vulnerability to '
                                      'require re-authentication for new '
                                      'identity providers'},
 'title': 'Dropbox Security Breach Exposes Flaw in Third-Party SSO '
          'Authentication',
 'type': 'Unauthorized Access',
 'vulnerability_exploited': 'Flawed email verification process in Lenovo IDs '
                            'and lack of secondary authentication for new SSO '
                            'logins in Dropbox'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.