Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Galaxy Z Fold 8 + Galaxy Watch 8/Ultra 2 up to $520 off, Pixel 11 models up to $322 off, more

    September 13, 2026

    Garmin releases major new update to high-end smartwatches with more than a dozen features and improvements

    September 13, 2026

    iPhone Duo can add fake bezel to the outside screen for better case compatibility

    September 13, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Sunday, September 13
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
    Reviews

    Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address

    myappsplusBy myappsplusSeptember 2, 2026003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts
    • Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact
    • Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup

    Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:

    Earlier this week, Dropbox started notifying affected individuals about the incident. In the data breach notification email, the company explains:

    “Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”

    Fixing the flaw

    In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.

    The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded.

    The vulnerability has since been addressed, and further steps taken to protect Dropbox users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID.

    “No one can access your Dropbox accountt said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts

    “Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration,” said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.

    “The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”

    Computing Computing Security Cyber Security Pro Security
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Austin Butler’s bedtime routine helped me fall asleep in minutes — a doctor explains why it works so fast

    September 13, 2026

    The first images of Meta’s Project Phoenix mixed reality headset have leaked — and there’s a reason it’s so thin and light

    September 13, 2026

    How to watch Great North Run 2026: Live stream online from anywhere for FREE

    September 13, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The 6 AI-free Linux distros I recommend most

    August 19, 20264 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views
    Latest Reviews

    Why Fluper is the No.1 Mobile App Development Company in the UAE, Saudi Arabia, and the Middle East.

    myappsplusAugust 18, 2026

    How New Kuwait And Indonesia Tech Deals At Baker Hughes (BKR) Have Changed Its Investment Story

    myappsplusAugust 18, 2026

    Google is reportedly planning to move all Pixel production out of China

    myappsplusAugust 18, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Why Fluper is the No.1 Mobile App Development Company in the UAE, Saudi Arabia, and the Middle East.

    August 18, 20260 Views

    How New Kuwait And Indonesia Tech Deals At Baker Hughes (BKR) Have Changed Its Investment Story

    August 18, 20260 Views

    Google is reportedly planning to move all Pixel production out of China

    August 18, 20260 Views
    Our Picks

    Galaxy Z Fold 8 + Galaxy Watch 8/Ultra 2 up to $520 off, Pixel 11 models up to $322 off, more

    September 13, 2026

    Garmin releases major new update to high-end smartwatches with more than a dozen features and improvements

    September 13, 2026

    iPhone Duo can add fake bezel to the outside screen for better case compatibility

    September 13, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.