Skip to main content
DropboxSecurity incident

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

What happened

Dropbox warned around 5,000 users that their accounts were compromised by attackers who abused a legacy Lenovo login integration, with attackers accessing files in fewer than a third of the affected accounts.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Security Cloud storage biz severs old integration and urges victims to reset credentials Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password. The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users. Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd. Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled. After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo...

Keep reading with a free account

The rest of this article, and every signal for Dropbox, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Issue
Legacy Lenovo login integration

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Legacy Lenovo login integration

Extraction

Confidence
100%
Detected
Sep 2, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Dropbox and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Dropbox this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/3d25def8-155a-f602-b4ae-1abd0dd1d6dd returns this record as JSON. POST /v1/companies/enrich returns every signal for dropbox.com.

{
  "signal_id": "3d25def8-155a-f602-b4ae-1abd0dd1d6dd",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-09-02T14:25:00+00:00",
  "company": {
    "name": "Dropbox",
    "domain": "dropbox.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924",
    "title": "Legacy Lenovo login opens 5,000 Dropbox accounts to attackers",
    "excerpt": "Security Cloud storage biz severs old integration and urges victims to reset credentials Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration. In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox blamed \"an issue with Lenovo's email verification process,\" which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts. It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password . The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users. Jameson Lopp , co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, \"IMPORTANT.rtf,\" which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd. Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled. After discovering the breach, Dropbox said it \"promptly expired all sessions logged in through Lenovo IDs\" and \"severed any link\" between the affected accounts and Lenovo. In...",
    "summary": "Dropbox warned around 5,000 users that their accounts were compromised by attackers who abused a legacy Lenovo login integration, with attackers accessing files in fewer than a third of the affected accounts.",
    "planning": false,
    "image_url": "https://image.theregister.com/5293949.jpg?imageId=5293949&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 1,
    "published_at": "2026-09-02T14:25:00Z",
    "vulnerability": "Legacy Lenovo login integration",
    "article_sentence": "Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration.",
    "related_company_name": "Lenovo",
    "related_company_domain": "lenovo.com"
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.