A security vulnerability in Dropbox's integration with Lenovo ID allowed unauthorized access to approximately 5,000 user accounts without requiring passwords. The flaw existed in the single sign-on (SSO) authentication process, which enabled attackers to create Dropbox accounts using only a victim's email address, without verifying actual access to that email.
The breach occurred between August 4 and 21. During this window, files were downloaded from roughly 1,500 of the compromised accounts. Dropbox has since patched the vulnerability and corrected the integration issue with Lenovo ID.