Dropbox said approximately 5,000 accounts were compromised between August 4 and August 21 after attackers exploited a legacy authentication link between Dropbox and Lenovo ID. Fewer than one-third of the affected accounts had files viewed or downloaded. The accounts lacked two-factor authentication, and attackers could register a Lenovo ID with another person’s email address to access the associated Dropbox account without the Dropbox password or email inbox. Dropbox has severed all connections between Lenovo IDs and Dropbox accounts, ended sessions authenticated through the integration, required users to enter their Dropbox password when accessing Dropbox through Lenovo, notified affected users and reported the incident to data protection regulators. Lenovo said its own customers were not affected and that its investigation was ongoing. DBX shares fell 2.64% to close at $34.26 on Tuesday. The incident comes amid broader warnings about state-linked and AI-enabled cyberattacks targeting critical infrastructure and financial markets.