ThreatPaper
Verified

Lenovo customers were not affected by the Dropbox incident

Assessment

Lenovo's statement, and it follows from the mechanism. The attack required registering a new Lenovo ID on the victim's email address; an address that already had a Lenovo ID could not be registered again, so existing Lenovo account holders were outside the attack surface. The affected population was Dropbox users who had never created a Lenovo ID. The statement is accurate about Lenovo's customers and says nothing about Lenovo's responsibility for the flaw, which Lenovo has acknowledged as an issue in "a legacy integration."

Where this claim appeared

Lenovo via BleepingComputer · 2026-09-02

https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 Accounts

Think this assessment is wrong? Report an error.