None of the 5,000 affected Dropbox accounts had two-factor authentication enabled
Assessment
The Register reports this from Dropbox and it is consistent with how the attack worked: Dropbox enforces 2FA at login regardless of which identity provider asserted the email, so an account with 2FA on would have stopped the attacker at the second factor. Users who reported enabling 2FA after a mid-August alert also reported no further access. Dropbox has not published the figure itself, but it is the one number in the incident that describes the affected population by cause rather than by count.
Where this claim appeared
The Register · 2026-09-02
https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924What “Verified” means
Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.
5 of 5 · rating scale
Assessed in
Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 AccountsThink this assessment is wrong? Report an error.