Lenovo ID email verification account-takeover security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A Lenovo ID email verification flaw let attackers register a Lenovo ID using a victim's email address and log into linked Dropbox accounts without the password. The weakness affected Dropbox users who relied on Lenovo Identity Provider Services for authentication, with accesses occurring between August 4 and 21. Dropbox and Lenovo mitigated the risk, and Dropbox now expires Lenovo-authenticated sessions and requires the Dropbox password for Lenovo ID authentication.
Related Happenings
Dropbox hit by cyberattack
Incident
H score17
First: 02.09.2026 15:30
Last: 02.09.2026 15:30
Sources 1
How related:
The attacker then used the fraudulent Lenovo ID to access the Dropbox account registered under the same email address without needing the login password.
About this happening:
Dropbox confirmed an unauthorized account access incident that let an attacker log into affected users’ accounts without the password, creating takeover risk. The access p...
Dropbox hit by cyberattack
IncidentHow related: The attacker then used the fraudulent Lenovo ID to access the Dropbox account registered under the same email address without needing the login password.
About this happening: Dropbox confirmed an unauthorized account access incident that let an attacker log into affected users’ accounts without the password, creating takeover risk. The access p...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
Campaign
H score34
First: 29.07.2026 20:54
Last: 29.07.2026 20:54
Sources 1
About this happening:
The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
ShinyHunters vishing and phishing campaign targeting healthcare and medical technology organizations
CampaignAbout this happening: The ShinyHunters campaign is intensifying vishing and phishing attacks against healthcare and medical technology organizations, increasing the risk of SSO takeover...
KDDI Corporation hit by network compromise
Incident
H score92
First: 24.06.2026 15:45
Last: 24.06.2026 15:45
Sources 1
About this happening:
KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detecte...
KDDI Corporation hit by network compromise
IncidentAbout this happening: KDDI Corporation confirmed an email-system breach that exposed customer credentials across six Japanese ISPs, putting account access at risk. The intrusion was detecte...
Latest development: 08.07.2026 14:24
Attackers breached the KDDI email platform used by five Japanese ISPs on May 16 after exploiting a zero-day vulnerability in third-party software, exposing email addresses and passwords across the affected service providers.
Meta AI-powered support tools abused in Instagram account recovery flow
Security Tool/Service
H score26
First: 02.06.2026 18:47
Last: 02.06.2026 18:47
Sources 1
About this happening:
Instagram accounts were hijacked after attackers abused Meta’s AI-powered support tools to pass recovery checks and change the recovery email, creating a direct failure in...
Meta AI-powered support tools abused in Instagram account recovery flow
Security Tool/ServiceAbout this happening: Instagram accounts were hijacked after attackers abused Meta’s AI-powered support tools to pass recovery checks and change the recovery email, creating a direct failure in...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive Guidance
H score41
First: 09.04.2026 17:02
Last: 09.04.2026 17:02
Sources 1
About this happening:
Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Phishing-resistant authentication to block post-breach credential abuse and relay attacks
Defensive GuidanceAbout this happening: Phishing-resistant authentication is being emphasized as the control that can stop post-breach account takeover when exposed email records fuel credential stuffing, AiTM...
Timeline
-
02.09.2026 15:30 2 articles · 1h ago
Fraudulent Lenovo IDs let attackers access Dropbox accounts
Initial DisclosureDropbox warned some users that an unauthorized party exploited an issue in Lenovo's email verification process to register fraudulent Lenovo IDs and then log into Dropbox accounts tied to the same email address without the Dropbox password. Dropbox said its authentication stack used Lenovo Identity Provider Services, and Lenovo said the issue involved a legacy integration between Lenovo ID and Dropbox that could improperly authenticate certain Dropbox accounts. Some users saw suspicious Dropbox sign-in notifications about two weeks earlier and changed their password and enabled two-factor authentication, while Dropbox and Lenovo mitigated the risk by expiring Lenovo-authenticated sessions and requiring the Dropbox password for Lenovo ID authentication.
Show sources
- Dropbox accounts breached through Lenovo email verification flaw — www.bleepingcomputer.com — 02.09.2026 15:30
- Dropbox accounts breached through Lenovo email verification flaw — www.bleepingcomputer.com — 02.09.2026 15:30