Dropbox
Disclosed Sep 2, 20263 weeks ago5,000 affectedUnverified
Lenovo ID verification flaw let attacker access about 5,000 Dropbox accounts
Dropbox notified users that a flaw in Lenovo's email verification let an attacker register Lenovo IDs with victims' emails and sign into about 5,000 linked Dropbox accounts between August 4 and 21, viewing and downloading some content.
What is known
| People affected | 5,000 (as reported by the organization) |
|---|---|
| Disclosed | Sep 2, 2026 |
| Attack | Vendor breach |
| Data exposed | Other |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Dropbox accounts breached through Lenovo email verification flawbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 2 | 5,000 |
Other breaches at Dropbox
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Material cybersecurity incident reported to the SEC (8-K Item 1.05)May 1, 20242 years ago | May 1, 20242 years ago | Not stated | Tech | Confirmed | Unknown |
| Phishing attack lets hacker steal 130 Dropbox GitHub repositoriesNov 1, 20223 years agoPhishingUnverified | Nov 1, 20223 years ago | Phishing | Tech | Unverified | Unknown |
| Stolen employee password leads to Dropbox user email theft; 68M credentials later leakJul 31, 201214 years agoCredential stuffing | Jul 31, 201214 years ago | Credential stuffing | Tech | Confirmed | 69M |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.