Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I’ve seen 2027’s new robot vacuums — here are 3 major trends set to level-up their cleaning, from drop-down suction boosters to… steam?

    September 13, 2026

    Is a free VPN worth using? Here’s why it could be risky

    September 13, 2026

    Creative Assembly says it was ‘a big deal’ to have player customization be a ‘must-have’ part of Total War: Warhammer 40,000 for fans of the tabletop game and hobby

    September 13, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Sunday, September 13
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
    Reviews

    Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address

    myappsplusBy myappsplusSeptember 2, 2026003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts
    • Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact
    • Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup

    Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:

    Earlier this week, Dropbox started notifying affected individuals about the incident. In the data breach notification email, the company explains:

    “Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”

    Fixing the flaw

    In other words, all criminals needed to have to pull this off was people’s email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.

    The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded.

    The vulnerability has since been addressed, and further steps taken to protect Dropbox users’ privacy. The company said it “promptly expired all sessions logged in through Lenovo IDs,” and terminated all links between Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID.

    “No one can access your Dropbox accountt said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts

    “Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration,” said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.

    “The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends.”

    Computing Computing Security Cyber Security Pro Security
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    I’ve seen 2027’s new robot vacuums — here are 3 major trends set to level-up their cleaning, from drop-down suction boosters to… steam?

    September 13, 2026

    ChatGPT Images 2.5 Cuts Latency and Fixes Edit Drift

    September 13, 2026

    Diablo 5 devs say that the game’s player character will have a “unique bond” with Diablo himself

    September 13, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The 6 AI-free Linux distros I recommend most

    August 19, 20263 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views
    Latest Reviews

    Apple Wallet driver’s licenses are coming to North Carolina, but there’s a catch

    myappsplusAugust 18, 2026

    3 Japanese AI Stocks Turning Automation Spending Into Real Revenue

    myappsplusAugust 18, 2026

    Apple: DOJ’s latest challenge in antitrust case ‘fails at every level’

    myappsplusAugust 18, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Apple Wallet driver’s licenses are coming to North Carolina, but there’s a catch

    August 18, 20260 Views

    3 Japanese AI Stocks Turning Automation Spending Into Real Revenue

    August 18, 20260 Views

    Apple: DOJ’s latest challenge in antitrust case ‘fails at every level’

    August 18, 20260 Views
    Our Picks

    I’ve seen 2027’s new robot vacuums — here are 3 major trends set to level-up their cleaning, from drop-down suction boosters to… steam?

    September 13, 2026

    Is a free VPN worth using? Here’s why it could be risky

    September 13, 2026

    Creative Assembly says it was ‘a big deal’ to have player customization be a ‘must-have’ part of Total War: Warhammer 40,000 for fans of the tabletop game and hobby

    September 13, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.