Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
SMRTR summary
Hackers exploited a flaw in Lenovo's email verification to break into around 5,000 Dropbox accounts between August 4 and 21, 2025, using only victims' email addresses to create fake Lenovo IDs. In roughly a third of breached accounts, stored files were viewed or downloaded. Dropbox has since ended Lenovo ID logins and urged users to enable two-factor authentication.
SMRTR provides this summary for quick context. The original article belongs to TechRadar.
Read the original article