CTIPilot

Dropbox

product · product:dropbox

Coverage timeline
1
first 2026-09-02 → last 2026-09-02
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

Releases covered
Dropbox
ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-02/dropbox-lenovo-id-sso-account-takeover · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-09-02/dropbox-lenovo-id-sso-account-takeover · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-02/dropbox-lenovo-id-sso-account-takeover · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-02/dropbox-lenovo-id-sso-account-takeover · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-09-02/dropbox-lenovo-id-sso-account-takeover · ATT&CK page ↗

Story timeline

  1. 2026-09-02Dropbox account takeover via a federated Lenovo-ID trust gap: roughly 5,000 accounts accessed with no password and no 2FA bypass needed
    active-threatsA broken email-verification check on one identity provider let attackers silently bind to any Dropbox account with 2FA disabled

Where this entity is cited

  • active-threats1

Source distribution

  • 9to5mac.com1 (33%)
  • freemalaysiatoday.com1 (33%)
  • heise.de1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Dropbox (1)

2026-09-02 · view entry permalink →

NOTABLENATOB1

Dropbox account takeover via a federated Lenovo-ID trust gap: roughly 5,000 accounts accessed with no password and no 2FA bypass needed

Dropbox confirmed to Reuters on 2026-09-02 that unauthorized parties accessed roughly 5,000 Dropbox accounts between 4 and 21 August 2026 by abusing "Continue with Lenovo," one of several third-party identity-provider login options Dropbox offers alongside Google and Apple (Reuters via Free Malaysia Today, 2026-09-02). The root cause is a broken trust chain spanning both parties. On Lenovo's side, the ID registration flow failed to verify that a registrant actually controlled the email address they supplied, so an attacker could register a brand-new Lenovo ID under a victim's known or guessed email address with no access to that inbox at all. On Dropbox's side, the relying-party logic then implicitly trusted the identity provider's asserted email claim to bind a login session to the matching Dropbox account (with no password prompt, no step-up challenge and no "link this new identity?" consent screen) whenever that account had Dropbox's own two-factor authentication disabled: "an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address" (Dropbox notification email, via 9to5Mac, 2026-09-01).

Once inside, attackers could browse account contents freely; per Dropbox, files were viewed or downloaded in fewer than a third of the roughly 5,000 affected accounts (heise Security, 2026-09-02). Reporting describes bulk, low-effort targeting rather than hand-picked victims, one reclaimed rogue Lenovo ID carried the throwaway display name "John Madden," the late NFL broadcaster (9to5Mac, 2026-09-01). Dropbox has since terminated every session authenticated via a Lenovo ID, severed the Lenovo–Dropbox account-linking integration entirely, and changed its system so a user's existing Dropbox password must now be entered before any Lenovo-ID-authenticated session can be established; it has reported the incident to data-protection regulators (Reuters via Free Malaysia Today, 2026-09-02). Lenovo separately confirmed the "legacy integration... could be used to improperly authenticate certain Dropbox accounts" and states its own customer accounts were not affected (Reuters via Free Malaysia Today, 2026-09-02).

Triage: a legitimate "Continue with Lenovo" (or any federated-IdP) login is ordinary traffic and is not distinguishable from this abuse pattern at the network layer, the discriminator lives in the relying party's own session and account-linking logs. The signal is a session established via a third-party IdP for an account that never previously had that IdP linked, immediately following a fresh registration on the IdP side, landing on an account with no second factor configured.

Dropbox told Reuters that it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, prompting the company to terminate all sessions authenticated through a Lenovo ID.

Reuters (via Free Malaysia Today) 2026-09-02

Lenovo identified a "legacy integration" between Lenovo ID and Dropbox that "could be used to improperly authenticate certain Dropbox accounts". The company said its own customers were not affected and that an investigation was ongoing.

Reuters (via Free Malaysia Today), quoting Lenovo

Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.

Dropbox, in its notification email to affected users (via 9to5Mac)

So konnte sich der Täter im Zeitraum 4. bis 21. August in rund 5.000 Dropbox-Konten frei umsehen. In weniger als einem Drittel der Fälle soll er Dateien gefunden haben, die ausreichend interessant erschienen, um sie herunterzuladen. (translated from German: The perpetrator was thus able to freely browse around 5,000 Dropbox accounts between 4 and 21 August. In fewer than a third of cases, they are said to have found files interesting enough to download.)

heise Security (Daniel AJ Sokolov)
incident02 Sep 05:20Zmulti-sourceOpen finding ↗