{
  "id": 5101949,
  "title": "Legacy Lenovo login opens 5,000 Dropbox accounts to attackers",
  "url": "https://urgent.news/2026/09/02/legacy-lenovo-login-opens-5-000-dropbox-accounts-to-attackers",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-02T14:25:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924"
  },
  "original_language": "en",
  "account": "Dropbox has alerted approximately 5,000 users that their accounts were compromised due to an exploit in a legacy Lenovo login integration. The cloud storage company attributed the breach to an issue with Lenovo's email verification process, which allowed attackers to register Lenovo IDs using the email addresses of Dropbox users and subsequently gain access to their accounts. This vulnerability persisted from August 4 to August 21.\n\nAccording to Dropbox, attackers accessed files belonging to fewer than a third of the affected users. Bitcoin security expert Jameson Lopp, co-founder of Casa, reported that a malicious party attempted to access one of his encrypted files, titled \"IMPORTANT.rtf,\" which had been uploaded to Dropbox prior to encryption.\n\nDropbox disclosed the extent of the breach to Reuters and stated that none of the affected accounts had two-factor authentication (2FA) enabled. Following the discovery of the attack, the company promptly terminated all sessions logged in through Lenovo IDs and severed any connection between the affected accounts and Lenovo. In its email to users, Dropbox advised them to change their Dropbox and personal email passwords, as well as enable 2FA.\n\nLenovo informed Reuters that its customers were not affected, and that its investigation was ongoing. The Register sought additional information from both Dropbox and Lenovo.",
  "summary": "Cloud storage biz severs old integration and urges victims to reset credentials",
  "key_points": [
    "Approximately 5,000 Dropbox accounts compromised due to Lenovo login exploit",
    "Attackers registered Lenovo IDs using affected users' email addresses",
    "Dropbox terminated sessions and severed connections after breach discovery"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Legacy Lenovo login opens 5,000 Dropbox accounts to attackers",
        "url": "https://urgent.news/2026/09/02/legacy-lenovo-login-opens-5-000-dropbox-accounts-to-attackers-5105648",
        "published": "2026-09-02T14:25:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}