HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Legacy Lenovo ID Integration Allows Hackers to Access 5,000 Dropbox Accounts

Hackers created spoofed Lenovo IDs, bypassed email verification, and used a legacy SSO link to log into 5,000 Dropbox accounts, exposing files for a subset of users. The incident underscores the need for rigorous identity‑access controls and continuous monitoring of third‑party integrations for audit readiness.

Verisq™ Intelligence · 📅 September 09, 2026 · 📰 bitdefender.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bitdefender.com

Legacy Lenovo ID Integration Allows Hackers to Access 5,000 Dropbox Accounts

What Happened – Attackers registered a new Lenovo ID using the email address of a Dropbox user, bypassed Lenovo’s email‑verification step, and then leveraged a legacy single‑sign‑on integration to log directly into the victim’s Dropbox account without a Dropbox password. Approximately 5,000 accounts were accessed between 4‑21 August 2026, and a subset of those had files viewed.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of weak third‑party identity verification – a core identity‑and‑access‑control objective that continuous‑control programs must monitor and evidence.
  • Highlights the need for documented third‑party integration reviews and real‑time alerts when legacy authentication pathways are used.
  • Shows how a single mis‑configured trust relationship can break the audit trail, making it harder to prove “who accessed what, when.”

Who Is Affected – Cloud‑based SaaS providers (e.g., Dropbox) that support external identity federation, and enterprises that rely on such federated logins for employee productivity.

Recommended Actions

  • Conduct an immediate audit of all third‑party SSO integrations; retire legacy flows that lack robust email or ownership verification.
  • Enforce mandatory password entry and multi‑factor authentication for every login, even when a federated identity is used.
  • Implement continuous monitoring of authentication events and retain immutable logs to support audit readiness.

Technical Notes – The exploit leveraged a legacy login integration between Lenovo ID and Dropbox. No software vulnerability (CVE) was involved; the weakness was the absence of email‑ownership validation in Lenovo’s registration process, which allowed attackers to create spoofed identities that were automatically trusted by Dropbox. Source: Bitdefender Blog

📰 Original Source
https://www.bitdefender.com/en-us/blog/hotforsecurity/lenovo-login-system-hackers-dropbox

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →