Dropbox Warns of Lenovo Verification Abuse

Dropbox warned some users that an unauthorized party accessed their accounts by abusing a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. The issue sits upstream of Dropbox itself: the attacker did not need Dropbox passwords to get in. In plain terms, a bogus Lenovo identity could be made to look trusted, and that trust was then used to reach linked Dropbox accounts. That matters because password theft, MFA checks, and suspicious Dropbox logins may not show the real entry point if the weakness is in the identity issuer. For any environment that lets third-party identities or verified emails open access, the exposure can live outside the SaaS login page. If the trust chain is broken upstream, the account can still look legitimate when it lands in Dropbox.

Part of the PlainSec briefing for 2026-09-02

Every edition of this story: Dropbox Warns of Lenovo Verification Abuse

Sources