ThreatPaper
Weak Evidence

A Lenovo login flaw breached 5,000 Dropbox accounts

Assessment

The framing, repeated across coverage, assigns the breach to Lenovo alone. Lenovo's flaw was real: its registration let anyone create a Lenovo ID on an unverified email address. But that only became a Dropbox account takeover because Dropbox accepted a first-time Lenovo assertion as a login for accounts that had never linked Lenovo, with no password check. Dropbox's own remediation, requiring the Dropbox password with Lenovo ID sign-in, is the admission that its side was missing a control. Two failures, one at each company; the claim names one.

Where this claim appeared

Pasquale Pillitteri · 2026-09-02

https://pasqualepillitteri.it/en/news/14388/dropbox-lenovo-id-login-flaw

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 Accounts

Think this assessment is wrong? Report an error.