About 5,000 Dropbox accounts were hijacked last month, and the attackers never had to guess a password.
Dropbox lets people log in using a verified Lenovo ID as an alternative to a Dropbox password. Between August 4 and 21, attackers exploited a flaw in Lenovo's email verification process to register a Lenovo ID using someone else's email address, then used that ID to walk straight into the matching Dropbox account. Most of the compromised accounts had no two-factor authentication turned on. In roughly a third of cases, Dropbox says stored files were viewed or downloaded.
This isn't really a Dropbox bug. It's a trust bug: Dropbox extended login privileges to a third-party identity system it didn't fully vet, and that system's weak verification became Dropbox's problem. It's the same failure mode that has burned single sign-on and OAuth integrations for years, where an account is only as secure as the weakest login path attached to it, not the platform with the biggest security team.
Dropbox has since cut the Lenovo ID login path loose and now requires a password even through that integration, a fix that doubles as an admission the shortcut should have required one from the start.