Dropbox's own infrastructure was not breached
Assessment
True and beside the point. No Dropbox server, database or credential store was compromised; the attacker walked through the Lenovo ID sign-in path exactly as Dropbox had configured it. Dropbox's notification, Lenovo's statement and every report agree. What the statement omits is that the configuration itself, binding a never-linked identity provider to an account on an email match with no password, was the vulnerability. An authentication path that admits the wrong person is a breach of the account whether or not any system was "hacked."
Where this claim appeared
shattered.io · 2026-09-02
https://shattered.io/dropbox-breach-5000-accounts-lenovo-id-2026/What “Verified” means
Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.
5 of 5 · rating scale
Assessed in
Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 AccountsThink this assessment is wrong? Report an error.