Dropbox Accounts Breached via Lenovo Email Verification Flaw
Unauthorized party exploited Lenovo's verification process to access user accounts

Key Takeaways
- Dropbox accounts were accessed unauthorizedly via a Lenovo email verification flaw.
- Threat actors registered fraudulent Lenovo IDs to facilitate the account compromise.
- Both Dropbox and Lenovo are investigating the incident and developing mitigations.
- Users are advised to enable two-factor authentication and monitor accounts for suspicious activity.
Quick answers
- What happened?
- Dropbox has warned that some user accounts were compromised after a threat actor exploited a flaw in Lenovo's email verification process. The actor used fraudulent Lenovo IDs, registered through the manipulated process, to gain unauthorized access to Dropbox accounts. Both companies are investigating the incident and advising users to secure their accounts.
- Which products are affected?
- Dropbox, Lenovo IDs
- What should defenders do?
- Users should enable two-factor authentication on Dropbox accounts, monitor accounts for suspicious activity, and follow official advisories from Dropbox and Lenovo for further updates.
According to a report from BleepingComputer published on September 2, 2026, Dropbox is warning certain users that an unauthorized party gained access to their accounts. The breach vector involved exploiting a flaw in Lenovo's email verification process. The threat actor used this vulnerability to register fraudulent Lenovo IDs, which were subsequently used to facilitate unauthorized access to Dropbox user accounts. Dropbox and Lenovo are reportedly working on mitigations, and users are advised to enable two-factor authentication and monitor their accounts for suspicious activity. The exact technical details of the email verification flaw and the full extent of affected users remain under investigation and have not been fully disclosed in official advisories as of the report date.
Security Details
Exploitation of a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs, which were then used to gain unauthorized access to Dropbox accounts.
Affected products
Dropbox, Lenovo IDs
Mitigation
Users should enable two-factor authentication on Dropbox accounts, monitor accounts for suspicious activity, and follow official advisories from Dropbox and Lenovo for further updates.
Sources
BleepingComputer
Dropbox accounts breached through Lenovo email verification flaw
Sep 2, 2026 · 12:30
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




