Dropbox said Tuesday that about 5,000 accounts were compromised, with hackers viewing and downloading content stored on the cloud storage platform.
According to Reuters, some Dropbox users received an email from the company Monday notifying them that their accounts had been accessed without authorization between Aug. 4 and Aug. 21. Hackers accessed files in fewer than one-third of the compromised accounts, the company said.
Dropbox told Reuters that it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have Dropbox’s two-factor authentication enabled. The company subsequently terminated all sessions authenticated through a Lenovo ID.
Dropbox has removed links between Lenovo IDs and Dropbox accounts and changed its systems so users must enter their Dropbox password before accessing an account through Lenovo. The company also said it reported the incident to data protection regulators.
READ: Instagram to label AI-generated profiles, limit reach of undisclosed accounts (September 1, 2026)
“We recently identified unauthorized access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled,” a Dropbox spokesperson told Decrypt. “Our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using another person’s email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”
“Approximately 5000 Dropbox accounts were impacted, and less than a third of these affected accounts had files viewed or downloaded,” the spokesperson added. “We’ve emailed all impacted users directly. Customers with questions about their account activity should contact our support team. If a user didn’t receive an email from us, their account was not impacted.”
READ: Meta to develop an AI agent platform Hatch for task completion (August 25, 2026)
The Reuters report also said Lenovo identified a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts.” The company said its own customers were not affected and that an investigation was ongoing.
Shares of Dropbox fell about 2.4% in extended trading Tuesday.
The incident came shortly after another major online security threat. On Tuesday, X users reported a surge of unsolicited password-reset emails, unfamiliar login alerts and account lockouts. X, however, said it had found no evidence of a new breach. An X engineer said attackers appeared to be attempting to take control of accounts to gain access to X Money.


