ThreatPaper
Assessed, Not Confirmed

Files were downloaded from roughly 1,500 of the compromised Dropbox accounts

Assessment

Dropbox's statement, as relayed by Reuters, is that the attacker "viewed and downloaded content from some users"; The Register renders the proportion as "fewer than one-third"; 9to5Mac's update converts that to "roughly 1,500." The 1,500 is arithmetic on Dropbox's proportion, not a figure Dropbox stated. It is a fair reading of "fewer than a third of 5,000" and should be cited as an approximation of Dropbox's characterisation rather than as Dropbox's number.

Where this claim appeared

9to5Mac · 2026-09-02

https://9to5mac.com/2026/09/02/dropbox-login-breach-seemingly-caused-by-egregious-authentication-failure/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 Accounts

Think this assessment is wrong? Report an error.