ThreatPaper
Verified

Dropbox's own infrastructure was not breached

Assessment

True and beside the point. No Dropbox server, database or credential store was compromised; the attacker walked through the Lenovo ID sign-in path exactly as Dropbox had configured it. Dropbox's notification, Lenovo's statement and every report agree. What the statement omits is that the configuration itself, binding a never-linked identity provider to an account on an email match with no password, was the vulnerability. An authentication path that admits the wrong person is a breach of the account whether or not any system was "hacked."

Where this claim appeared

shattered.io · 2026-09-02

https://shattered.io/dropbox-breach-5000-accounts-lenovo-id-2026/

What “Verified” means

Established by primary sources — the original disclosure, a vendor incident report, a court filing, a government advisory, or the affected party itself. Where a claim is material, at least two independent sources agree.

5 of 5 · rating scale

Assessed in

Dropbox via Lenovo ID: How a Third Party's Email Check Became a Password Bypass for 5,000 Accounts

Think this assessment is wrong? Report an error.