Lenovo Flaw Exposed 5,000 Dropbox Accounts Through Identity Federation

A person leans toward a laptop on a wooden desk, with a plant and books nearby, in natural light.

Letting one company vouch for a login into another company’s app has become routine. It saves a step, but it hands part of that account’s security to a vendor nobody chose. Dropbox just found out what that costs. The cloud-storage provider is warning roughly 5,000 customers that intruders reached their accounts through its identity federation with Lenovo, the PC maker. No Dropbox password was required. BleepingComputer, a security-news outlet, first reported the breach and traced it to a flaw in how Lenovo verifies who owns an email address.

How a Fake Lenovo ID Reached a Real Dropbox Account

Dropbox lets people sign in through Lenovo Identity Provider Services, one of several single sign-on (SSO) options tied to Lenovo’s account system. Anyone with a verified Lenovo ID can reach the Dropbox account tied to that email. The attacker exploited a bug in how Lenovo confirms who owns an email address. They used a fraudulent Lenovo ID to walk straight into a victim’s Dropbox account. Dropbox trusted that confirmation and never asked the account holder to verify through an existing login. Some of those roughly 5,000 people never had a Lenovo account.

Lenovo’s email check broke first. The warning sign surfaced instead on Dropbox’s own login screen. A user named xaphod noticed a new “Continue with SSO” option on the login page, despite never creating a Lenovo ID. The bug lived at Lenovo, but its only visible symptom appeared inside Dropbox, a password-free account takeover with no Dropbox credential involved. A company can run flawless authentication and still get breached through a partner’s mistake. It is the same third-party risk that keeps surfacing as a blind spot in identity security. Lenovo called the issue a legacy integration between Lenovo ID and Dropbox and said its own customers were not affected.

Closing the Identity Federation Gap After the Dropbox Breach

Lenovo has closed the integration. The broader flaw sits wherever a company hands login security to an outside identity provider. Dropbox has expired every session that came in through a Lenovo ID. It now requires the Dropbox password before any Lenovo ID login goes through. Any company running federated single sign-on carries the same exposure.

Inventory every federated login path into each tenant – Dropbox’s link to Lenovo went unmapped for years before this breach surfaced it. A trust link nobody wrote down is one nobody is watching.

Confirm ownership locally before honoring a partner’s assertion – the tell sat on Dropbox’s own login screen, a new “Continue with SSO” option, days before anyone traced it to Lenovo. Checking a partner’s assertion against the account’s own login is cheap, and delegated identity keeps becoming the leading path into the enterprise.

The convenience that let a Lenovo ID open a Dropbox account has not gone away. Neither has the flaw that turned it into a data breach without a single password. Identity federation quietly made Lenovo part of Dropbox’s login security. The attacker worked that out before Dropbox did.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display