Home ComputersDropbox Breach Traced to Broken Lenovo SSO Linking — No Real Step-Up Auth

Dropbox Breach Traced to Broken Lenovo SSO Linking — No Real Step-Up Auth

Dropbox accounts cracked via Lenovo SSO — because linking didn’t require a real login check

by Roronoa Zoro
0 views

Dropbox has been emailing users about unauthorized account access between August 4 and August 21, 2026, tied to a single sign-on path using Lenovo IDs. 9to5Mac, citing The Cybersecurity Help-style analysis, says Lenovo’s email verification was weak — but the deeper failure is Dropbox accepting a newly linked SSO identity without forcing the existing Dropbox login, step-up challenge, or explicit “link this identity?” consent.

Attack pattern in plain language: collect target emails, abuse the broken link flow, walk into the account. Dropbox frames vendor email verification as the spark; security writers argue any IdP link without binding to the already-authenticated user is an application design bug. Rotate passwords, kill unknown sessions, and treat surprise SSO providers as hostile until proven otherwise.

Source: https://9to5mac.com/2026/09/01/dropbox-login-breach-seemingly-caused-by-egregious-authentication-failure/