Dropbox warned some users that a Lenovo email verification flaw let attackers create IDs tied to victims' email addresses. Linked identity flows need confirmation from the account being protected.
BleepingComputer reported on September 2, 2026, that Dropbox warned some users their accounts were accessed after attackers exploited a Lenovo email verification issue to create fraudulent Lenovo IDs.
The important lesson is about connected identity. When one login system trusts another system's email verification too broadly, an attacker may not need the victim's original password to reach the account being protected. Dropbox later expired affected sessions and added an extra password requirement for that login path.
Why it matters for verification
Email verification is powerful because many services treat email ownership as proof of identity. But account recovery should not depend on a single weak signal when files, payments, private messages, or business accounts are at stake.
BillioPlus checklist
- Review connected apps, linked identity options, and active sessions on important accounts.
- Enable MFA and prefer passkeys where available.
- Do not ignore unexpected single sign-on prompts or new login options on an account.
- Use separate recovery details for high-value personal, business, and admin accounts.
Source links
Tags
Chinedu Celestine Okpala
BillioPlus Team · Content & Guides
