{
  "id": 5105648,
  "title": "Legacy Lenovo login opens 5,000 Dropbox accounts to attackers",
  "url": "https://urgent.news/2026/09/02/legacy-lenovo-login-opens-5-000-dropbox-accounts-to-attackers-5105648",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-02T14:25:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924"
  },
  "original_language": "en",
  "account": "Dropbox has alerted approximately 5,000 users that their accounts were compromised due to an exploitation of a legacy Lenovo login integration. In an email to those affected, the cloud storage company claimed that attackers took advantage of an integration that enabled users to access Dropbox using Lenovo IDs. Dropbox attributed the issue to an email verification process problem by Lenovo, which allowed attackers to register Lenovo IDs using Dropbox users' email addresses, consequently gaining access to the respective storage accounts. They did not clarify why access was provided without necessitating the user to input a Dropbox password.\n\nThe breach persisted from August 4 to 21. Dropbox informed Bloomberg that attackers accessed less than a third of the affected users' files. Jameson Lopp, co-founder of Bitcoin security company Casa, stated that attackers tried to access only one of his files, named 'IMPORTANT.rtf,' which was encrypted locally prior to being uploaded to Dropbox. At times, it's advantageous to possess expertise in certain areas. Dropbox confirmed the extent of the attack to Reuters and disclosed that none of the affected accounts had two-factor authentication (2FA) activated. Upon discovering the breach, Dropbox immediately terminated all sessions logged in through Lenovo IDs and severed any connection between the affected accounts and Lenovo.\n\nIn its email, the company recommended affected users to change their Dropbox and personal email passwords and enable 2FA. Lenovo stated to Reuters that its customers remained unharmed, and its investigation was ongoing. The Register sought further details from both Dropbox and Lenovo.",
  "summary": "Cloud storage biz severs old integration and urges victims to reset credentials",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Legacy Lenovo login opens 5,000 Dropbox accounts to attackers",
        "url": "https://urgent.news/2026/09/02/legacy-lenovo-login-opens-5-000-dropbox-accounts-to-attackers",
        "published": "2026-09-02T14:25:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}