Dropbox says a broken Lenovo integration let strangers log into other people's accounts without ever knowing their password.
The issue traces back to Lenovo ID, the account system Lenovo uses for its own services. Someone could register a Lenovo ID using another person's email address, then use that identity to sign into the matching Dropbox account through a legacy Lenovo-Dropbox login integration. The integration failed to properly verify that the email address actually belonged to the person creating the Lenovo ID. Dropbox says about 5,000 accounts were compromised this way between August 4 and August 21.
This isn't a Dropbox password leak or a brute-force attack. It's a failure in a decade-old trust handshake between two companies' login systems. Single sign-on integrations are convenient because they let one company vouch for a user's identity to another, but that convenience only works if the vouching company actually confirms who owns the email address it's vouching for.
Five thousand accounts is a small slice of Dropbox's user base, but the bigger question is how many other legacy sign-in integrations, quietly bolted onto major platforms years ago, still skip a verification step this basic.