The Next Web
Dropbox says 5,000 accounts were breached through a Lenovo login

Dropbox confirmed that a legacy Lenovo ID integration allowed attackers to register a Lenovo account with a victim’s email and access the victim’s Dropbox without a password, compromising about 5,000 accounts between August 4-21. All affected accounts lacked multi-factor authentication; Dropbox terminated the integration, forced native passwords, and notified users, while both companies reported the breach to regulators.