frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Dropbox Data Breach

19•hmate9•6h ago
I received a security notice from Dropbox today saying that my account was accessed without authorization between August 4 and August 21, 2026, and that Dropbox believes files in the account were viewed or downloaded.

According to the email, Dropbox uses Lenovo as an identity provider, allowing users to authenticate to Dropbox with a verified Lenovo ID.

Dropbox says:

an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.

So, as I understand it, the attack path was roughly:

1. Attacker registers a Lenovo ID using the victim’s email address. 2. Lenovo incorrectly treats the email address as verified. 3. Dropbox trusts the Lenovo identity. 4. Attacker gets access to the Dropbox account associated with that email address.

Dropbox says it has since expired all sessions authenticated through Lenovo ID and removed the Lenovo link from my account. It also says Lenovo authentication can no longer be used for the account without first entering the Dropbox password.

I’ve searched for a public disclosure from Dropbox or Lenovo and haven’t found one yet.

Has anyone else received the same notice, or seen any public information about this vulnerability?

I’m particularly interested in knowing how broadly the Lenovo ID login mechanism was available and how many Dropbox accounts may have been affected.

Comments

latexr•6h ago
> Has anyone else received the same notice, or seen any public information about this vulnerability?

Another submission on HN (to Twitter).

https://news.ycombinator.com/item?id=49514471

xaphod•5h ago
I got this same email about an hour ago.

About two weeks ago I received a notification from Dropbox that somebody signed in that I did not recognize. I immediately changed my password and enabled 2FA. There were no open unknown sessions or any activity that seemed suspicious other than that one login.

One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID.

Ask HN: What would happen if your company stopped using all AI tomorrow?

30•jc_811•12h ago•51 comments

Dropbox Data Breach

19•hmate9•6h ago•2 comments

Old.reddit.com no longer works for logged out users

18•kradeelav•3h ago•7 comments

Claude Code now appends a link to a Claude session in every commit

5•codexon•4h ago•1 comments

Ask HN: What do your job interviews look like?

24•Hixon10•1d ago•7 comments

Claude 20x usage is only for the 5 hour window, not for the weekly limit

13•vmg12•13h ago•3 comments

Ask HN: Why is Founder Mode not working for Airbnb?

5•jorisboris•19h ago•6 comments

Native Apps Why?

6•dmvjs•15h ago•14 comments

Ask HN: Which self-hosted Docker UIs support rootless mode?

3•vsilent•15h ago•0 comments

Tell HN: PayPal blocks GrapheneOS

514•leumon•4d ago•325 comments

Ask HN: What is the next Burning Man in NA?

3•johnnyApplePRNG•17h ago•6 comments

Ask HN: What to do when a vendor doesn't respond to security issues?

3•cudder•18h ago•2 comments

Ask HN: Are Prompt Injections "Malware"?

2•razorbeamz•18h ago•9 comments

Ask HN: Is Rust is a real niche programming language?

3•juntz•19h ago•2 comments

Ask HN: What are your biggest problems and fixes with multisession engineering?

5•top_rooster•1d ago•2 comments

Which AI Do You Think Will Have the Greatest Impact on the World?

4•SudilaDasun•1d ago•3 comments

You Are the Harness

5•learningstud•1d ago•0 comments

Is a One Person Company (OPC) just another type of Uber driver?

6•Bobby_Liu•1d ago•10 comments

Ask HN: AI for Home Lab Infra?

2•voakbasda•1d ago•3 comments

Ask HN: Do you run A/B Tests?

5•hackeryogi•1d ago•4 comments

You've reached the end!