Tertius News is an AI-native newsroom: an AI model reads the linked source articles below and extracts what each outlet reported, so you can compare their coverage side by side. How this works →
Dropbox Says Hackers Breached About 5,000 Accounts via Lenovo ID Login
Dropbox has confirmed that hackers accessed about 5,000 user accounts in August after exploiting an issue with Lenovo's email verification process. The company said files were viewed or downloaded on less than a third of those accounts, and it has since notified regulators and affected users.
By Tertius News AI Desk2 distinct · 3 mastheads · 3 articlesVersion 1Coverage Published
Dropbox has confirmed that hackers breached approximately 5,000 user accounts in August, accessing files on a minority of them after exploiting a flaw in Lenovo's email verification system. The company said it has since notified regulators and affected users.
The intrusion, which the cloud-storage company disclosed in an email to some users on Aug. 31, allowed unauthorized access to accounts between Aug. 4 and Aug. 21, according to notification emails seen by Bloomberg News. The company told some users their files were viewed and downloaded during that period, while others were told there was no evidence of such activity, the emails show.
Spokesperson Tim Rathschmidt said in an email that about 5,000 accounts were compromised, with files accessed on less than a third of them. The accounts involved were not protected by multi-factor authentication, he said.
According to the company and to notification emails, the attackers used a Lenovo ID — a username and password that lets users access products and services from Lenovo Group. Dropbox users can log in using verified Lenovo IDs, but an “issue” with Lenovo's email verification process allowed hackers to register Lenovo IDs using Dropbox users' email addresses, even if the users had not set up such an account. The hackers then used those IDs to access the Dropbox accounts.
Justin Kalland, a tech engineer, wrote on X that he received an email from Dropbox on Aug. 7, 2026, alerting him to a new sign-in. In a subsequent notice, Dropbox told him it had observed unauthorized access to his account between Aug. 4 and Aug. 21, adding that logs showed no evidence that his files were viewed or downloaded.
The company explained that it is an active partner of Lenovo and that Lenovo users can access Dropbox using verified Lenovo IDs. It said its investigation determined “that an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using the user's email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”
Rathschmidt said Dropbox moved to secure the accounts once it learned of the issue. The company has since terminated all sessions authenticated through a Lenovo ID, removed the link between Lenovo IDs and Dropbox accounts, and modified its systems to require users to enter their Dropbox password before accessing an account via Lenovo, according to statements from the company. Dropbox also said it has reported the incident to data protection regulators.
Lenovo said in an emailed statement that it recently became aware of a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts.” The two companies worked together to “mitigate the risk.” Lenovo said its customers were not affected and that an investigation is ongoing.
Rathschmidt said Dropbox does not expect the breach to have a material impact on its business. Shares of Dropbox fell as much as 6.6 percent in post-market trading on Tuesday, Reuters reported.
How each outlet told it
A framing line is our reading of that outlet's own text — an interpretation, not a quotation and not a fact we assert. Check it against what the outlet published.
Framing: The headline emphasizes the breach of user accounts by hackers who accessed data.
Facts Included:
Hackers broke into thousands of Dropbox Inc. accounts last month, viewing and downloading material users kept on the cloud-storage platform, according to a company statement and records seen by Bloomberg News
About 5,000 Dropbox accounts were compromised by the hackers, who accessed files on less than a third of them, spokesperson Tim Rathschmidt said in an email
When Dropbox learned of the issue, it moved to secure the accounts, he said, adding that the company has since notified regulators and affected users
Framing: The headline emphasizes the data breach of about 5,000 Dropbox users, attributed to a Lenovo login glitch, and sets the event in August 2026.
Facts Included:
Hackers compromised Dropbox data from around 5,000 users using a Lenovo login, the cloud-storage platform confirmed in an email to users.
The company's spokesperson Tim Rathschmidt said that cybercriminals accessed files on less than a third of them.
According to the company's statement and records reviewed by Bloomberg News, hackers viewed and downloaded materials from thousands of Dropbox users in August.
Some users received an email from the company on Monday, August 31, after Bloomberg reported on the hack, stating that their accounts had been accessed without authorisation between August 4 and August 21.
The company said that cybercrooks compromised files in fewer than a third of the compromised accounts.
Engineer Justin Kalland wrote on X that Lenovo's email verification flaw allowed hackers to connect Dropbox accounts.
Kalland claimed that he received an email from the cloud storage platform, saying, "We noticed a new sign-in to your Dropbox account" on August 7, 2026.
Dropbox said in an email to Kalland that they observed unauthorised access to his account between August 4 and August 21, 2026, while logs showed no evidence that files were viewed or downloaded.
Dropbox said that, as the company is an active partner of laptop manufacturer Lenovo, Lenovo users can log in to their Dropbox accounts using verified Lenovo IDs.
The Dropbox email read that an issue with Lenovo's email verification process allowed an unauthorised party to register a Lenovo ID using the user's email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.
The email further stated that Dropbox promptly expired all sessions logged in through Lenovo IDs and severed any link between Lenovo and the Dropbox account.
Shares of Dropbox fell around 4% in extended trading on Tuesday, according to the news agency Reuters.
Dropbox told Reuters that it identified unauthorised access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, prompting the company to terminate all sessions authenticated through a Lenovo ID.
Dropbox said that it had reported the cyberattack to data protection regulators, removed links between Lenovo IDs and Dropbox accounts, and changed its systems, allowing users to enter their Dropbox password before accessing an account through Lenovo.
Framing: The headline emphasizes the breach of Dropbox user accounts by hackers who accessed data.
Facts Included:
Hackers broke into thousands of Dropbox accounts in August, viewing and downloading material users kept on the cloud storage platform, according to a company statement and records seen by Bloomberg News.
About 5,000 Dropbox accounts were compromised by the hackers, who accessed files on less than a third of them, spokesperson Tim Rathschmidt said in an e-mail.
When Dropbox learnt of the issue, it moved to secure the accounts, he said, adding that the company has since notified regulators and affected users.
Some Dropbox users received an e-mail from the company on Aug 31 saying there was unauthorised access to their accounts between Aug 4 and Aug 21, according to notification e-mails seen by Bloomberg.
The company told some users their files were viewed and downloaded during that time, while others were told there was no evidence of this, the e-mails show.
The compromised accounts were not protected by multi-factor authentication, Rathschmidt said.
The hackers accessed the accounts by using a Lenovo ID, a user name and password that allows users to access products and services made by Lenovo Group, according to the e-mails.
Dropbox users can access their accounts using verified Lenovo IDs, according to one of the e-mails.
Because of an “issue” with Lenovo’s e-mail verification process, the hackers were able to register Lenovo IDs using the emails of Dropbox users, even if they had not set up such an account, the notification e-mails say.
The hackers then used the Lenovo IDs’ to access the accounts.
Lenovo said in an e-mailed statement that it recently became aware of a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts”.
The companies worked together to “mitigate the risk”.
Lenovo’s customers were not affected,and an investigation is ongoing, according to the statement.
Dropbox does not expect the breaches to have a material impact on its business, Rathschmidt said.
AI-extracted; can misattribute a claim — see Methodology.
Each row is one claim, attributed to the outlet whose wording states it most clearly. Confidence rates how directly the source text states the claim — explicit and unhedged rates high; hedged, pieced-together, or internally inconsistent statements rate lower. It does not measure whether the claim is true. Status is Contested when two claims on this page negate each other; otherwise it counts the distinct outlets we found asserting that specific claim — so a single-source claim can still show high confidence, and a multi-source claim can show medium. Every one of those outlets is named beside the status, so you can check the count against the list. For claims extracted before we began storing that list, the row says so: it names the outlet the claim is quoted from and states that we have not recorded which outlets backed it. Outlets wrote at different times, so a figure that evolves — a casualty count, for example — can legitimately differ between rows; check the "as of" time next to each claim's source.
Claim
Confidence
Status
ClaimHackers compromised Dropbox data from around 5,000 users using a Lenovo login, the cloud-storage platform confirmed in an email to users.
ClaimAccording to the company's statement and records reviewed by Bloomberg News, hackers viewed and downloaded materials from thousands of Dropbox users in August.
ClaimSome Dropbox users received an email from the company on Monday, August 31, after Bloomberg reported on the hack, stating that their accounts had been accessed without authorisation between August 4 and August 21.
ClaimKalland claimed that he received an email from the cloud storage platform, saying, "We noticed a new sign-in to your Dropbox account" on August 7, 2026.
ClaimDropbox said in an email to Kalland that they observed unauthorised access to his account between August 4 and August 21, 2026, while logs showed no evidence that files were viewed or downloaded.
ClaimDropbox said that, as the company is an active partner of laptop manufacturer Lenovo, Lenovo users can log in to their Dropbox accounts using verified Lenovo IDs.
ClaimThe Dropbox email read that an issue with Lenovo's email verification process allowed an unauthorised party to register a Lenovo ID using the user's email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.
ClaimThe email further stated that Dropbox promptly expired all sessions logged in through Lenovo IDs and severed any link between Lenovo and the Dropbox account.
ClaimDropbox told Reutersthat it identified unauthorised access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, prompting the company to terminate all sessions authenticated through a Lenovo ID.
ClaimDropbox said that it had reported the cyberattack to data protection regulators, removed links between Lenovo IDs and Dropbox accounts, and changed its systems, allowing users to enter their Dropbox password before accessing an account through Lenovo.
ClaimWhen Dropbox learnt of the issue, it moved to secure the accounts, he said, adding that the company has since notified regulators and affected users.
ClaimThe hackers accessed the accounts by using a Lenovo ID, a user name and password that allows users to access products and services made by Lenovo Group, according to the e-mails.
ClaimLenovo said in an e-mailed statementthat it recently became aware of a “legacy integration” between Lenovo IDand Dropboxthat “could be used to improperly authenticate certain Dropbox accounts”.
ClaimSome Dropbox users received an e-mail from the company on Aug 31 saying there was unauthorised access to their accounts between Aug 4 and Aug 21, according to notification e-mails seen by Bloomberg.
ClaimThe company told some users their files were viewedand downloaded during that time, while others were told there was no evidence of this, the e-mails show.