Dropbox has confirmed that hackers breached approximately 5,000 user accounts in August, accessing files on a minority of them after exploiting a flaw in Lenovo's email verification system. The company said it has since notified regulators and affected users.

The intrusion, which the cloud-storage company disclosed in an email to some users on Aug. 31, allowed unauthorized access to accounts between Aug. 4 and Aug. 21, according to notification emails seen by Bloomberg News. The company told some users their files were viewed and downloaded during that period, while others were told there was no evidence of such activity, the emails show.

Spokesperson Tim Rathschmidt said in an email that about 5,000 accounts were compromised, with files accessed on less than a third of them. The accounts involved were not protected by multi-factor authentication, he said.

According to the company and to notification emails, the attackers used a Lenovo ID — a username and password that lets users access products and services from Lenovo Group. Dropbox users can log in using verified Lenovo IDs, but an “issue” with Lenovo's email verification process allowed hackers to register Lenovo IDs using Dropbox users' email addresses, even if the users had not set up such an account. The hackers then used those IDs to access the Dropbox accounts.

Justin Kalland, a tech engineer, wrote on X that he received an email from Dropbox on Aug. 7, 2026, alerting him to a new sign-in. In a subsequent notice, Dropbox told him it had observed unauthorized access to his account between Aug. 4 and Aug. 21, adding that logs showed no evidence that his files were viewed or downloaded.

The company explained that it is an active partner of Lenovo and that Lenovo users can access Dropbox using verified Lenovo IDs. It said its investigation determined “that an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the user's email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”

Rathschmidt said Dropbox moved to secure the accounts once it learned of the issue. The company has since terminated all sessions authenticated through a Lenovo ID, removed the link between Lenovo IDs and Dropbox accounts, and modified its systems to require users to enter their Dropbox password before accessing an account via Lenovo, according to statements from the company. Dropbox also said it has reported the incident to data protection regulators.

Lenovo said in an emailed statement that it recently became aware of a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts.” The two companies worked together to “mitigate the risk.” Lenovo said its customers were not affected and that an investigation is ongoing.

Rathschmidt said Dropbox does not expect the breach to have a material impact on its business. Shares of Dropbox fell as much as 6.6 percent in post-market trading on Tuesday, Reuters reported.