Attackers have reportedly found a way into Dropbox accounts without needing a password, by registering Lenovo IDs using victims' email addresses. The technique allows them to sign into existing Dropbox accounts as if they were the account owner, according to reports.
The attack method
The attackers reportedly create a Lenovo ID using the victim's email address. Because that email address is already associated with a Dropbox account, the newly created Lenovo ID appears to grant access to the Dropbox account without requiring the account's password. The exact technical details of how the two services interact are not yet public, but the attack appears to bypass the need for a password entirely.
What's at stake
Dropbox accounts often contain personal files, work documents, and other sensitive data. If attackers gain access, they could read, download, or even delete those files. The scope of the attack is unknown, and it is not clear how many accounts have been affected. The attack is notable because it does not rely on stolen passwords or phishing; it exploits the trust between two separate services.
No official response yet
Neither Lenovo nor Dropbox has publicly commented on the reports. It is unclear whether either company has taken steps to block the attack or notify affected users. Security researchers are likely investigating the issue, but no details have been released. The lack of a public statement leaves users in the dark about the severity of the problem.
What users can do
For now, the safest course for Dropbox users is to be alert for any unusual activity on their accounts. Checking login history and reviewing connected apps could help spot unauthorized access. However, without official guidance from the companies, it is difficult to know what specific steps to take. Users who believe they may be affected should consider changing their passwords and enabling two-factor authentication if they haven't already.
The attack highlights a growing concern: the use of email addresses as universal identifiers across different services. When one service allows an email address to be used to create an account, and another service trusts that email address as proof of identity, the potential for abuse exists. This is not the first time such a flaw has been reported, but it serves as a reminder that passwords are not the only line of defense.
Dropbox users who believe they may be affected should consider changing their passwords and enabling two-factor authentication if they haven't already. But until Lenovo and Dropbox address the issue, the full extent of the problem remains unclear.




