From August 4 to 21, 2026, numerous Dropbox users were alarmed to receive security alerts indicating that their accounts had been accessed without their authorization. Upon investigation, it was revealed that this security breach was not a result of a direct attack on Dropbox's systems. Instead, it stemmed from a trust-related vulnerability in the integration between Lenovo ID registration and the Dropbox Single Sign-On (SSO) login mechanism. Dropbox has promptly implemented measures to safeguard user accounts and has notified all affected individuals about the incident.
