Dropbox Lenovo ID Breach: Check Account and File Access

Daniel Zimmermann
7 Min Read
An email-shaped key opens an alternate lock on a folder of Dropbox files.
The Lenovo ID incident shows how an alternate sign-in route can expose cloud files.

Attackers accessed about 5,000 Dropbox accounts through a flaw in Lenovo ID authentication, including accounts belonging to people who had never created a Lenovo ID themselves. Dropbox says the affected accounts lacked its two-factor authentication; files were accessed in fewer than one-third of them. If you received a notice, open Dropbox independently and review your account access before following any links in the message. A compromised account and confirmed file copying require different responses. [1] [2]

How a Lenovo ID opened a Dropbox account

Dropbox’s notification describes an email-verification problem that let someone register a Lenovo ID using another person’s address. That identity could then sign in to the corresponding Dropbox account without its password. Lenovo described the issue as involving a legacy integration. This was an identity-linking failure: you did not need to buy a Lenovo computer, intentionally connect a Lenovo account, or disclose your Dropbox password for the reported mechanism to matter. [1]

The reported access occurred between August 4 and August 21, 2026. Dropbox terminated Lenovo-authenticated sessions, removed the account links, and added a Dropbox-password requirement for that sign-in route. Those changes close the reported access path; they cannot retrieve a file already copied elsewhere. [2]

What your situation means

  • No notice and no unfamiliar activity: the headline alone does not establish that your account was accessed. Check the email address attached to Dropbox, including its spam folder, and review account security. Ask Dropbox support if you find unexplained activity; do not submit credentials to a third-party “breach checker.”
  • A notice says there is no evidence of files being viewed or downloaded: preserve that distinction. It still describes unauthorized account access, but it is not confirmation that every document was stolen. Follow the account-security steps below.
  • Dropbox confirms file access: secure the account, then identify which information those files contained. A tax document, password list, work contract, or API key creates different follow-up tasks. Do not assume that renaming or deleting the cloud copy neutralizes an attacker’s copy.
  • An unfamiliar session, device, or app remains: record its details, revoke its access, and contact support if it returns. A new event does not by itself prove that the original Lenovo flaw is still exploitable.
  • You cannot sign in: use Dropbox’s own password-reset and support routes, reached from its official site. Ignore anyone asking for payment, a one-time code, or remote control to “recover” the account. [3]

A public example of the notification says that the recipient’s files showed no evidence of viewing or downloading. That finding belongs to that account. It must not be generalized to every affected user. Likewise, the company’s “fewer than one-third” statement is not a precise count of stolen files. [1] [2]

Check sessions, devices, and apps separately

Open your usual Dropbox app or type the service address yourself. In account Settings → Security, inspect browser sessions and linked devices. Check My apps for connected applications. If you suspect unauthorized access, change your Dropbox password and enable two-factor authentication; review available passkeys as another sign-in option. Protect the email account used for recovery too. [3]

The device list covers desktop and mobile app sign-ins. A web-only login does not necessarily appear as a linked device, so an empty device list is not a complete account-access check. To remove an unfamiliar device, use the trash icon beside it and confirm Unlink. Dropbox cautions that files already synchronized to a computer can remain accessible there after remote sign-out. [4]

Review sharing on sensitive files as well. A shared link and direct membership are separate ways to reach a document: removing an unwanted member may not invalidate a link, and deleting a link does not necessarily remove a person who has direct access. Check both before considering sharing contained. [5]

If documents were viewed or downloaded

Make a short inventory of the affected material using the notification and any details support can provide. Preserve the notice, relevant timestamps, and filenames without posting the documents publicly. If work or customer information was involved, give that inventory to your organization’s security or privacy contact.

For credentials stored in an exposed document, change or revoke those credentials at the service that issued them. For business payment instructions, verify any subsequent change request through a known contact. For personal identity documents, follow the issuing authority’s advice if misuse appears or a confirmed notice recommends action. These are conditional consequences of the file contents, not claims that Dropbox exposed every type of information.

The incident does not establish malware on your computer. A local scan cannot determine whether a cloud document was copied. However, a follow-up message may use the news as a pretext: our Dropbox email scam guide explains why even a recognizable cloud-share message needs independent verification. A suspicious follow-up domain can also be checked with Gridinsoft Website Reputation Checker; a clean result does not authenticate a message or justify entering a password.

References

  1. Dropbox. Customer notification reproduced in Ben Lovejoy, “Dropbox breach seemingly caused by egregious authentication failure.” 9to5Mac, updated September 2, 2026. Dropbox customer notification.
  2. Fabiola Arámburo and Mrinmay Dey. “Dropbox says about 5,000 accounts compromised in August hack.” Reuters, September 1, 2026; updated September 2, 2026. Dropbox’s statement to Reuters.
  3. Dropbox. “Accessing Dropbox from a new location.” Dropbox Help, updated August 31, 2026; accessed September 3, 2026. Account-security checks.
  4. Dropbox. “How to view your devices and log out remotely.” Dropbox Help, updated August 29, 2025; accessed September 3, 2026. Devices and remote sign-out.
  5. Dropbox. “How to unshare files and folders in Dropbox.” Dropbox Help, accessed September 3, 2026. Shared links and membership.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?