Dropbox is telling some users their accounts got hacked - and the break-in reportedly ran through Lenovo's login system, not Dropbox's own defenses.
Dropbox recently emailed a group of customers warning that an attacker had accessed their accounts last month. The company points to Lenovo's ID system, a single sign-on layer some users rely on to log into Dropbox, as the entry point. Dropbox has not said how many accounts were hit or what data the attacker saw. The warning email landed roughly a month after the reported access, a gap that will draw its own scrutiny.
This is the trade-off single sign-on always carries: convenience for the user, shared blast radius for everyone downstream. A weakness in one company's identity system can expose customers of an entirely different company, with no flaw required in that second company's own code.
It's the same lesson enterprises learned from Okta's run of identity-provider incidents - outsourcing your login screen doesn't outsource the risk that comes with it.