A Lenovo login flaw breached 5,000 Dropbox accounts
Assessment
The framing, repeated across coverage, assigns the breach to Lenovo alone. Lenovo's flaw was real: its registration let anyone create a Lenovo ID on an unverified email address. But that only became a Dropbox account takeover because Dropbox accepted a first-time Lenovo assertion as a login for accounts that had never linked Lenovo, with no password check. Dropbox's own remediation, requiring the Dropbox password with Lenovo ID sign-in, is the admission that its side was missing a control. Two failures, one at each company; the claim names one.
Where this claim appeared
Pasquale Pillitteri · 2026-09-02
https://pasqualepillitteri.it/en/news/14388/dropbox-lenovo-id-login-flawWhat “Weak Evidence” means
Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.
3 of 5 · rating scale
Assessed in
Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 AccountsThink this assessment is wrong? Report an error.