HeadlinesBriefing favicon HeadlinesBriefing.com

Dropbox breach reveals SSO authentication failure with Lenovo IDs

9to5Mac •
×

Multiple Dropbox users were notified of unauthorized account access between August 4 and August 21, 2026. The breach occurred through a flaw in Lenovo's email verification process, allowing attackers to register Lenovo IDs using victim email addresses. Despite this external vulnerability, Dropbox's own authentication failure was the primary issue.

The company permitted single sign-on login via Lenovo IDs without requiring users to verify the new identity or use existing login credentials. This lack of step-up authentication allowed implicit account linking, where Dropbox trusted the Lenovo ID's email claim and minted a session without password prompts or consent. Security researcher Yoni Levy shared the breach notice on X.

The attacker compiled target emails from breach corpora and LinkedIn lists, then registered rogue Lenovo IDs. Dropbox has since fixed the flaw and expired all sessions authenticated through Lenovo IDs. The Cyber Sec Guru noted that even if Lenovo's verification failed, Dropbox should have authenticated the linked ID before granting access.

Certified refurbished Apple products 15% off at apple.com and other advertisements appear in the original source.