Trending Topics

Dropbox hacks confirm that authentication must not start and end at the login page
Up to 5,000 Dropbox users have received emails notifying them that their accounts were compromised by attackers in August. And the compromises were big: these accounts had been accessed without authorisation for a two-week period. Although Dropbox said that less than a third of the impacted accounts had their files accessed by the attackers, the seriousness of the attack methodology can’t be ignored by security teams at any organisation.
Dropbox told Reuters that the security incident involved accounts that were linked to some Lenovo ID’s without two-factor authentication enabled. Lenovo says that a legacy integration was behind the incident, which led to the improper authentication of some Dropbox accounts.
There are a number of lessons to be learned from this particular set of account compromises. “Every single one of the compromised accounts lacked multi-factor authentication,” said Muhammad Yahya Patel, vCISO & Cybersecurity Advisor at Huntress. “In 2026, for cloud storage accounts holding data, that’s an indefensible gap, and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration.”
There’s no arguing with that conclusion from me.
Then there’s the inherent trust issue. “This is the same failure mode we keep seeing across every major vendor breach this year,” Justin Beals, CEO & Founder of Strike Graph, told me. “Organisations assess the vendors they contract with directly, then treat every integration that vendor maintains as inherited trust.”
Dropbox hacks: The key lesson to learn
This is where the headline lesson comes in: authentication cannot be allowed to both start and end at the account login page.
If that assumption is made, then attackers will find insecure relationships – such as the legacy Lenovo integration in this case – and they will exploit them.
“Lenovo’s verification process could be abused to create an account using someone else’s email address,” said Piyush Sharma, CEO at Tuskira, “and Dropbox trusted that identity enough to let the attacker in.”
Dropbox has now taken action, removing the links between Lenovo IDs and Dropbox accounts and making changes requiring users to enter a Dropbox password before accessing any account through Lenovo.
But unless security teams audit what third-party services have authentication access, stop trusting third-party connections just because a trusted partner or platform has built them.
As Sharma concluded: “Keep reevaluating who trusts whom and what that trust actually gives access to.” This won’t be the last such incident we will report on.
