In August 2026, approximately 5,000 Dropbox user accounts were breached by hackers who accessed and downloaded user files between August 4 and August 21, according to Dropbox and multiple reports [1, 2, 3]. Less than one-third of the compromised accounts had files viewed or downloaded by the hackers [1, 2, 3].

Dropbox spokesperson Tim Rathschmidt said, "The compromised accounts were not protected by multi-factor authentication," noting the lack of additional security on affected accounts [1]. The breach occurred through a vulnerability in the integration between Lenovo ID and Dropbox authentication systems [1, 2, 3]. Due to a flaw in Lenovo's email verification process, hackers registered Lenovo IDs using Dropbox users' email addresses, allowing them to bypass authentication controls [1, 2, 3].

After discovering the issue, Dropbox disabled all Lenovo ID-based logins and severed the linkage between Lenovo ID and Dropbox accounts. The company also changed the system to require users to enter their Dropbox password before logging in via Lenovo ID [2, 3]. Dropbox notified the affected users by email on August 31 and reported the incident to data protection regulators [1, 2, 3].

Lenovo released a statement saying it "recently became aware of a 'legacy integration' between Lenovo ID and Dropbox that 'could be used to improperly authenticate certain Dropbox accounts'. Lenovo’s customers were not affected and an investigation is ongoing," confirming the issue originated from an older integration with Dropbox [1, 2, 3].

Following the public confirmation of the breach on September 1, Dropbox's stock price fell in after-hours trading that day. Reports vary: one source said shares dropped as much as 6.6%, while others recorded a roughly 2.4% decline [1, 2, 3].

The unauthorized access period from August 4 to August 21 marks the timeframe when hackers exploited the Lenovo ID vulnerability. Dropbox’s notification to affected users came on August 31, with a public statement following September 1 after media reports surfaced [1, 2, 3].