Start your day with intelligence. Get The OODA Daily Pulse.
Dropbox partners with Lenovo as a federated identity provider, so a user can sign in to Dropbox with a “verified” Lenovo ID instead of a password. According to breach notification emails sent to affected users beginning around August 31, 2026, Dropbox’s investigation found that a defect in Lenovo’s email verification process let an unauthorized party register a Lenovo ID under any email address, including addresses they didn’t control, and then present that Lenovo ID to Dropbox. Dropbox matched the email claim to an existing account and granted a session. The attacker never broke cryptography, phished a password or touched Dropbox’s storage layer. What they exploited was more mundane, and more dangerous: assumptions about who vouches for an email address inside a federated trust relationship.
Full report : Dropbox breach seemingly caused by egregious authentication failure.