HeadlinesBriefing favicon HeadlinesBriefing.com

Dropbox breach caused by authentication failure

9to5Mac •
×

Multiple Dropbox users have been emailed by the cloud storage company to advise them that a security breach saw unauthorised access to their account. Update: the company has said that about 5,000 accounts were compromised, with files downloaded from around 1,500 of them. The root cause appears to be a lack of authentication by Dropbox when attackers created a single sign-on option through a third-party company.

Developer Yoni Levy posted a copy of the email he received on X. The email stated that unauthorized access occurred between August 4 and August 21, 2026, and that Dropbox partnered with Lenovo as an identity provider. An issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the victim's email address and then use that ID to log into the Dropbox account.

While Dropbox claims the flaw was in Lenovo's email verification process, the bigger issue appears to be that Dropbox itself did not require users to use their existing login to verify the new SSO. The attacker could register a rogue ID, use federated sign-in, and Dropbox would resolve the email claim to the existing account without a password prompt or consent.

9to5Mac's Take: While there was certainly a failure to verify email addresses at the Lenovo end, it would not have done any harm if Dropbox had authenticated the linked ID before it could be used to sign in. Failing to do so is an egregious fault. The company has now fixed the flaw and expired all sessions previously 'authenticated' through a Lenovo ID. If you don't already have two-factor authentication enabled for Dropbox, it is highly recommended to change this immediately.