Close Menu
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
Trending

Ethena Expands USDe into Global Payments with New App

6 minutes ago

Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw

8 minutes ago

Federalism Will Save the Data Centers

34 minutes ago
Facebook X (Twitter) Instagram
Facebook X (Twitter) Discord Telegram
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Market Data Newsletter
Tuesday, September 1
  • Home
  • News
    • Politics
    • Legal & Courts
    • Tech & Big Tech
    • Campus & Education
    • Media & Culture
    • Global Free Speech
  • Opinions
    • Debates
  • Video/Live
  • Community
  • Freedom Index
  • About
    • Mission
    • Contact
    • Support
FSNN | Free Speech News NetworkFSNN | Free Speech News Network
Home»Cryptocurrency & Free Speech Finance»Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw
Cryptocurrency & Free Speech Finance

Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw

News RoomBy News Room8 minutes agoNo Comments3 Mins Read0 Views
Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw
Share
Facebook Twitter Pinterest Email Copy Link

Listen to the article

0:00
0:00

Key Takeaways

Playback Speed

Select a Voice

In brief

  • Dropbox notified users of unauthorized account access between August 4 and August 21 after attackers reportedly exploited a Lenovo ID authentication issue.
  • One affected user received an alert showing a login from near Canary Wharf in London using Chrome on Windows.
  • Dropbox said it found no evidence that files were viewed or downloaded and has since changed how Lenovo IDs can access accounts.

Multiple Dropbox users were notified that unauthorized parties accessed their accounts through an authentication flaw involving Lenovo ID.

The incident appears to have exploited the way Dropbox handled single sign-on, or SSO, through Lenovo IDs. Dropbox said an issue with Lenovo’s email verification process allowed unauthorized parties to register Lenovo IDs using other people’s email addresses and then use those identities to access the Dropbox accounts associated with the same addresses.

Myriad: Tesla highs in September? Click to make your prediction.

In a letter to affected users, Dropbox said accounts were accessed without authorization between August 4 and August 21, 2026, though the company said logs showed no evidence that files were viewed or downloaded.

“We recently identified unauthorized access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled,” a Dropbox spokesperson told Decrypt. “Our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using another person’s email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”

“Approximately 5000 Dropbox accounts were impacted, and less than a third of these affected accounts had files viewed or downloaded,” the spokesperson added. “We’ve emailed all impacted users directly. Customers with questions about their account activity should contact our support team. If a user didn’t receive an email from us, their account was not impacted.”

Developer Yoni Levy, one of the affected users, posted screenshots of the letter on X.

One screenshot shows Dropbox warning Levy that a new web browser had signed into his account from “Near Canary Wharf, England, United Kingdom” on August 18 at 6:06 a.m. local time. The login used Chrome on Windows.

Levy said he had never had a Lenovo account and had not been to the United Kingdom.

A subsequent notification from Dropbox told Levy that its investigation found an unauthorized party had registered a Lenovo ID using his email address and then used that ID to log into his Dropbox account.

The attack did not appear to require a victim’s Dropbox password or access to their email inbox. According to Dropbox, affected accounts were linked to Lenovo IDs and did not have Dropbox two-factor authentication enabled, allowing attackers to use newly registered Lenovo IDs with matching email addresses to access existing accounts without additional verification.

The warning follows other account-security scares affecting major online platforms.

On Tuesday, X users reported a surge of unsolicited password-reset emails, unfamiliar login alerts and account lockouts, though X said it had found no evidence of a new breach. An X engineer said attackers appeared to be attempting to take control of accounts to gain access to X Money.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Read the full article here

Fact Checker

Verify the accuracy of this article using AI-powered analysis and real-time sources.

Get Your Fact Check Report

Enter your email to receive detailed fact-checking analysis

5 free reports remaining

Continue with Full Access

You've used your 5 free reports. Sign up for unlimited access!

Already have an account? Sign in here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link
News Room
  • Website
  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn

The FSNN News Room is the voice of our in-house journalists, editors, and researchers. We deliver timely, unbiased reporting at the crossroads of finance, cryptocurrency, and global politics, providing clear, fact-driven analysis free from agendas.

Related Articles

Cryptocurrency & Free Speech Finance

Ethena Expands USDe into Global Payments with New App

6 minutes ago
Media & Culture

Federalism Will Save the Data Centers

34 minutes ago
Cryptocurrency & Free Speech Finance

Ethena pushes stablecoins into everyday banking with high-yield savings, cards and payments

60 minutes ago
Cryptocurrency & Free Speech Finance

Kalshi Issues First Lifetime Ban for Republican Politician over Insider Bets

1 hour ago
Cryptocurrency & Free Speech Finance

Bitcoin’s Next Move: Bullish Bets Run Up Against a Historical Wall

1 hour ago
Media & Culture

X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching

2 hours ago
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw

8 minutes ago

Federalism Will Save the Data Centers

34 minutes ago

Ethena pushes stablecoins into everyday banking with high-yield savings, cards and payments

60 minutes ago

Kalshi Issues First Lifetime Ban for Republican Politician over Insider Bets

1 hour ago
Latest Posts

Bitcoin’s Next Move: Bullish Bets Run Up Against a Historical Wall

1 hour ago

X Kills Nitter And Xcancel, The Last Ways To Read Tweets Without Elon Watching

2 hours ago

Kalshi Says It’s a Prediction Market. The 9th Circuit Says It’s Gambling.

2 hours ago

Subscribe to News

Get the latest news and updates directly to your inbox.

At FSNN – Free Speech News Network, we deliver unfiltered reporting and in-depth analysis on the stories that matter most. From breaking headlines to global perspectives, our mission is to keep you informed, empowered, and connected.

FSNN.net is owned and operated by GlobalBoost Media
, an independent media organization dedicated to advancing transparency, free expression, and factual journalism across the digital landscape.

Facebook X (Twitter) Discord Telegram
Latest News

Ethena Expands USDe into Global Payments with New App

6 minutes ago

Dropbox Security Breach: Hackers Access Accounts Through Authentication Flaw

8 minutes ago

Federalism Will Save the Data Centers

34 minutes ago

Subscribe to Updates

Get the latest news and updates directly to your inbox.

© 2026 GlobalBoost Media. All Rights Reserved.
  • Privacy Policy
  • Terms of Service
  • Our Authors
  • Contact

Type above and press Enter to search. Press Esc to cancel.

🍪

Cookies

We and our selected partners wish to use cookies to collect information about you for functional purposes and statistical marketing. You may not give us your consent for certain purposes by selecting an option and you can withdraw your consent at any time via the cookie icon.

Cookie Preferences

Manage Cookies

Cookies are small text that can be used by websites to make the user experience more efficient. The law states that we may store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies, we need your permission. This site uses various types of cookies. Some cookies are placed by third party services that appear on our pages.

Your permission applies to the following domains:

  • https://fsnn.net
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Statistic
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.