A Lenovo email-verification flaw opened 5,000 Dropbox accounts without a password
On September 2, 2026, Dropbox disclosed that an attacker accessed roughly 5,000 accounts by abusing a flaw in Lenovo’s email-verification process to register fraudulent Lenovo IDs — never needing the victim’s Dropbox password. Audit every identity-federation link you accept and require re-authentication on SSO sign-ins.