Dropbox has disclosed that roughly 5,000 user accounts were accessed without authorization between August 4 and August 21 through a legacy Lenovo ID sign-in integration. In fewer than one-third of the affected accounts, the intruders viewed or downloaded stored files.
The company has begun notifying affected users. According to the reported details, the compromised accounts did not have two-factor authentication enabled.

The incident was tied to Dropbox accounts connected to Lenovo that could use Lenovo ID for authentication. Lenovo described the feature as a legacy integration that could have enabled improper sign-in to certain accounts.
Dropbox has ended sessions authenticated through Lenovo ID, removed the association between Lenovo IDs and Dropbox accounts, and changed the sign-in flow. Users who previously relied on the Lenovo ID route must now enter their Dropbox password as part of authentication.

Dropbox reported the incident to data-protection authorities and disabled the affected mechanism. The disclosure points to an account-access issue involving an older third-party authentication path, rather than evidence that Dropbox's broader cloud infrastructure was compromised.







