Dropbox has been emailing users about unauthorized account access between August 4 and August 21, 2026, tied to a single sign-on path using Lenovo IDs. 9to5Mac, citing The Cybersecurity Help-style analysis, says Lenovo’s email verification was weak — but the deeper failure is Dropbox accepting a newly linked SSO identity without forcing the existing Dropbox login, step-up challenge, or explicit “link this identity?” consent.
Attack pattern in plain language: collect target emails, abuse the broken link flow, walk into the account. Dropbox frames vendor email verification as the spark; security writers argue any IdP link without binding to the already-authenticated user is an application design bug. Rotate passwords, kill unknown sessions, and treat surprise SSO providers as hostile until proven otherwise.