Dropbox hit by cyberattack
Incident
Summary
Hide ▲
Show ▼
Dropbox confirmed an unauthorized account access incident that let an attacker log into affected users’ accounts without the password, creating takeover risk. The access path relied on fraudulent Lenovo IDs created through Lenovo’s email verification process and linked to Dropbox through Lenovo Identity Provider Services. Dropbox said the accesses occurred between August 4 and 21. The company expired Lenovo-authenticated sessions and now requires the Dropbox password for Lenovo ID authentication.
Related Happenings
Lenovo ID email verification account-takeover security flaw
Vulnerability
H score51
First: 02.09.2026 15:30
Last: 02.09.2026 15:30
Sources 1
How related:
an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address
About this happening:
A Lenovo ID email verification flaw let attackers register a Lenovo ID using a victim's email address and log into linked Dropbox accounts without the password. The weakne...
Lenovo ID email verification account-takeover security flaw
VulnerabilityHow related: an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address
About this happening: A Lenovo ID email verification flaw let attackers register a Lenovo ID using a victim's email address and log into linked Dropbox accounts without the password. The weakne...
KDDI Corporation hit by network compromise
Incident
H score92
First: 24.06.2026 15:45
Last: 24.06.2026 15:45
Sources 1
About this happening:
KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detecte...
KDDI Corporation hit by network compromise
IncidentAbout this happening: KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detecte...
Latest development: 08.07.2026 14:24
Attackers breached the KDDI email platform used by five Japanese ISPs on May 16 after exploiting a zero-day vulnerability in third-party software, exposing email addresses and passwords across the affected service providers.
Meta AI-powered support tools abused in Instagram account recovery flow
Security Tool/Service
H score26
First: 02.06.2026 18:47
Last: 02.06.2026 18:47
Sources 1
About this happening:
Instagram accounts were hijacked after attackers abused Meta’s AI-powered support tools to pass recovery checks and change the recovery email, creating a direct failure in...
Meta AI-powered support tools abused in Instagram account recovery flow
Security Tool/ServiceAbout this happening: Instagram accounts were hijacked after attackers abused Meta’s AI-powered support tools to pass recovery checks and change the recovery email, creating a direct failure in...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive Guidance
H score41
First: 09.04.2026 17:02
Last: 09.04.2026 17:02
Sources 1
About this happening:
Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive GuidanceAbout this happening: Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Microsoft Entra device code phishing and vishing campaign
Campaign
H score40
First: 19.02.2026 14:30
Last: 19.02.2026 14:30
Sources 1
About this happening:
A device code phishing campaign is targeting Microsoft 365 identities through the OAuth 2.0 device authorization flow, letting attackers steal valid access tokens afte...
Microsoft Entra device code phishing and vishing campaign
CampaignAbout this happening: A device code phishing campaign is targeting Microsoft 365 identities through the OAuth 2.0 device authorization flow, letting attackers steal valid access tokens afte...
Timeline
-
02.09.2026 15:30 2 articles · 1h ago
Dropbox warns of account access via fraudulent Lenovo IDs
Initial DisclosureDropbox warned some users that an unauthorized party accessed their accounts by abusing Lenovo’s email verification process to register fraudulent Lenovo IDs and then use those IDs to log into the Dropbox accounts associated with the same email addresses without the password. Dropbox said the affected accesses occurred between August 4 and 21, and that Dropbox and Lenovo mitigated the risk by expiring all Lenovo-authenticated sessions and requiring the Dropbox password for Lenovo ID authentication.
Show sources
- Dropbox accounts breached through Lenovo email verification flaw — www.bleepingcomputer.com — 02.09.2026 15:30
- Dropbox accounts breached through Lenovo email verification flaw — www.bleepingcomputer.com — 02.09.2026 15:30