Search the Dropbox Watchdog archive
Yes. Between 4 and 21 August 2026, an attacker used a flaw in Lenovo's own email-verification process — not a flaw in Dropbox's password system — to register a Lenovo ID on a victim's email address, and Dropbox's 'Continue with Lenovo' sign-in link then trusted that identity without asking for a Dropbox password, reaching roughly 5,000 linked Dropbox accounts.
The root cause, as reported convergently by BleepingComputer, The Register, and 9to5Mac, was an "issue with Lenovo's email verification process" that let an unauthorized party register a Lenovo ID using someone else's email address. Because Dropbox's Lenovo ID sign-in option linked accounts through that identity, BleepingComputer reported that Dropbox's identity-linking process "trusted Lenovo's assertion that the attacker controlled the email address without requiring confirmation through the existing Dropbox login method" — so the attacker could enter a linked Dropbox account without ever supplying, or needing, a Dropbox password.
Reporting converges on roughly 5,000 affected accounts, but splits on how many had files actually touched: The Register reported "attackers accessed files belonging to fewer than a third" of them, and 9to5Mac put a number on that fraction, reporting "files downloaded from around 1,500 of them." The Register additionally reported that, according to Dropbox, none of the affected accounts had two-factor authentication enabled.
Dropbox's reported remediation was to expire "all sessions logged in through Lenovo IDs," sever the Lenovo integration link on affected accounts, and add a new login requirement mandating that users enter their Dropbox account password when signing in via Lenovo ID going forward. Reuters reported that "Dropbox said it had reported the incident to data protection regulators." As of this archive's most recent check, Dropbox has not published a public security advisory or incident report about the event.
For context, this wasn't the year's only Dropbox reliability story: Dropbox's own status page separately logged eleven service incidents between January and September 2026, including a roughly 93-hour shared-content-download degradation in June — unrelated to the Lenovo breach, but a reminder that 2026 was a bumpy year for Dropbox's operational track record on more than one front.
This answer is informational, not legal or security advice. Dropbox Watchdog is independent and not affiliated with Dropbox, Inc.