Dropbox Got Hacked and Nobody Even Needed a Password

Dropbox Got Hacked and Nobody Even Needed a Password

Passwords, multi-factor authentication, security questions with answers only you could possibly know, we build all these locks and then, every so often, a company hands out a spare key through a door nobody was watching. That's essentially what just happened to Dropbox, care of a Lenovo login integration.

An Identity Handoff Gone Wrong

Dropbox confirmed on September 1, 2026, that roughly 5,000 user accounts were compromised through a flaw in a Lenovo ID integration, not a breach of Dropbox's own systems. A broken email-verification process let an attacker register a Lenovo ID using someone else's email address, then use that freshly minted Lenovo ID to log straight into the Dropbox account tied to that same email, no password required.

Unauthorized access occurred between August 4 and August 21, 2026, and while Dropbox says logs show no confirmed evidence of mass file exfiltration, files were viewed or downloaded on a portion of the affected accounts. Every single compromised account, notably, had multi-factor authentication turned off.

The Weak Link Was the Handshake, Not the Vault

This wasn't Dropbox getting popped, it was Dropbox trusting a third party's identity check that turned out to have a hole in it. Third-party login integrations are convenience features until the day they quietly become your biggest attack surface, and most users have no idea how many of these silent handshakes are attached to their accounts.

The detail worth sitting with: MFA would have stopped every single one of these takeovers cold. Zero compromised accounts had it enabled, which makes this less a story about a clever hack and more a story about a setting nobody bothered to flip on.

A free lock is still a lock, and apparently a lot of people just aren't using theirs.

If your business relies on third-party SSO or login integrations, it's worth an honest audit of what they can actually authorize on your behalf, our free security checklist is a solid place to start.

Source: Bloomberg