Dropbox hack exposes 5,000 accounts as hackers access and download users’ files
Dropbox said hackers compromised around 5,000 user accounts last month, gaining unauthorized access to its cloud storage service and, in some cases, viewing and downloading files. The breach traces back to a legacy connection with Lenovo ID, exposing a weak link outside Dropbox’s standard login flow.
Some Dropbox users received emails Monday informing them that their accounts had been accessed without permission between August 4 and August 21. Dropbox confirmed the incident after Bloomberg News reported the breach earlier in the day.
“Hackers broke into thousands of Dropbox Inc. accounts last month, viewing and downloading material users kept on the cloud-storage platform,” Bloomberg reported, citing a company statement and records.
“About 5,000 Dropbox accounts were compromised by the hackers, who accessed files on less than a third of them, spokesperson Tim Rathschmidt said in an email. When Dropbox learned of the issue, it moved to secure the accounts, he said, adding that the company has since notified regulators and affected users,” the report added.
The intrusion goes beyond stolen login details. Dropbox said hackers accessed files in fewer than a third of the compromised accounts. That means potentially hundreds of users had content stored inside their Dropbox accounts exposed to outsiders.
Investors reacted quickly. Dropbox shares fell about 2.4% in extended trading Tuesday following news of the breach.
Dropbox told Reuters that its investigation found unauthorized access affecting accounts connected to Lenovo ID that did not have two-factor authentication enabled. The company responded by terminating every Dropbox session authenticated through Lenovo ID.
Dropbox has since removed links between Lenovo IDs and Dropbox accounts. Users who previously relied on the integration must now enter their Dropbox password before accessing their accounts through Lenovo.
The company said it reported the incident to data protection regulators.
A legacy integration becomes a security liability
Lenovo identified the source as a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts”. Lenovo said its own customers were not affected and that its investigation remains underway, Reuters reported.
The incident highlights a security problem that can linger long after partnerships and integrations fade from view. A cloud account may have strong security controls at its front door, yet an older authentication path connected to another service can create another route in.
That distinction matters here. Dropbox isn’t describing a conventional attack in which hackers simply cracked thousands of Dropbox passwords. The unauthorized access stemmed from an external identity integration, and the affected accounts lacked two-factor authentication.
This isn’t Dropbox’s first major security incident. In May 2024, the company disclosed a breach of Dropbox Sign, its eSignature service formerly known as HelloSign, after an unidentified threat actor gained unauthorized access to its production environment.
Dropbox said the attacker accessed data tied to all Dropbox Sign users, including email addresses, usernames and general account settings. For some users, the exposed information went much deeper, including phone numbers, hashed passwords, API keys, OAuth tokens and multi-factor authentication information.
Dropbox discovered the breach on April 24, 2024, according to a Form 8-K filed with the U.S. Securities and Exchange Commission. Dropbox said at the time, “The threat actor had accessed data related to all users of Dropbox Sign, such as emails and usernames, in addition to general account settings.”
The two incidents are separate, but they share a familiar security concern: authentication. The 2024 breach exposed authentication information for some Dropbox Sign users, and the latest incident involved accounts connected through a legacy Lenovo ID authentication integration.
The latest hack comes roughly three months after Dropbox founder Drew Houston stepped down as CEO to pursue AI ventures, closing a nearly two-decade run leading the company he started with Arash Ferdowsi in 2007.
Houston famously came up with the idea after repeatedly forgetting his USB drive while studying at MIT. Dropbox went through Y Combinator and became one of the accelerator’s earliest breakout companies. Houston later became the first founder to take a Y Combinator-backed startup from the program to the public markets.
Dropbox grew from a simple file-syncing tool into a cloud storage company serving hundreds of millions of people and businesses. Nearly two decades later, the latest breach shows how cloud security can depend on something users may rarely think about: an old authentication connection that can still open the door.

