Cloud storage provider Dropbox confirmed a security breach affecting approximately 5,000 user accounts between 4 August and 21 August 2026. The compromise was traced to an email verification vulnerability in a legacy integration with Lenovo Group's authentication service (Lenovo ID). Threat actors exploited the flaw by registering unauthorized Lenovo IDs using victim email addresses to bypass passwords and access linked Dropbox accounts that lacked multi-factor authentication (MFA). Dropbox confirmed that hackers viewed or downloaded files in less than one-third of the impacted accounts (~1,600 users). In response, Dropbox severed all Lenovo ID authentication links, invalidated active sessions, notified data protection regulators and impacted users, and mandated Dropbox password authentication for future logins.