OptMsg Breach Breakdown card: Dropbox logo on a white panel, for the September 2026 Dropbox account breach.

Dropbox Data Breach — What Happened and What To Do

Around the middle of August, a Dropbox user opened his account settings and noticed something he had not set up: the sign-in page was offering him “Continue with SSO,” using a Lenovo ID he had not created. He did not own a Lenovo anything. Then Dropbox’s notice arrived, saying someone else had been inside his account.

That is the whole shape of this incident, and it is worth understanding even if you were not one of the roughly 5,000 people it happened to — because nobody stole a password to do it.

Confirmation: confirmed by company — Dropbox’s notification to affected users, and Dropbox’s on-record figures to Reuters and Bloomberg. This incident is not listed on Have I Been Pwned, because no dataset was published.

What Company Was Breached?

Dropbox, the cloud storage service, confirmed that about 5,000 user accounts were accessed by an unauthorized party between August 4 and August 21, 2026. The weakness was not in Dropbox’s own password system. Dropbox used Lenovo Identity Provider Services as one of the ways a person could sign in, and Lenovo’s email verification process allowed someone to register a Lenovo ID using an email address they did not own. Dropbox then accepted that Lenovo ID as proof that the person owned the Dropbox account tied to the same email address.

Lenovo has described it as a legacy integration between Lenovo ID and Dropbox and says its own customers were not affected. Dropbox has said that none of the affected accounts had two-factor authentication turned on.

When Did the Breach Occur?

The unauthorized access ran from August 4 to August 21, 2026; Dropbox has notified affected users by email, and the incident was reported publicly on September 1 and 2. Some users say they received Dropbox “suspicious sign-in” alerts roughly two weeks before the story broke, which lines up with the access window.

What Was Stolen?

Dropbox told Bloomberg that files were viewed or downloaded in fewer than a third of the roughly 5,000 affected accounts; no list of email addresses or passwords was published from this incident. That last part matters, and it is the opposite of most breaches we write about. The attackers did not get your email address from Dropbox — they already had it, and used it to register a Lenovo ID. What was exposed was what sat inside the affected accounts: documents, photos, whatever those users kept there.

Dropbox has not published a breakdown of what kinds of files were taken. If you received a notification, assume the contents of your account were readable to a stranger during those seventeen days.

How Can This Breach Be Used Against You?

The most likely follow-on is not another break-in — it is a fake “Dropbox security notice” sent to people who have heard about this story. A well-publicised account compromise is the perfect cover for a phishing message: “We detected suspicious activity on your Dropbox account. Confirm your identity here.” The link goes to a page that collects your real password, the one the attackers did not have.

For the people whose files were actually downloaded, the risk depends on what was in them. A scanned passport, a tax return, a spreadsheet of logins — anything that was sitting in a Dropbox folder is now the raw material for identity theft or for a very convincing targeted scam.

How to Protect Yourself

  1. If Dropbox emailed you, do what the notice says: change your Dropbox password, change the password on the email account tied to it, and turn on two-factor authentication for both. Dropbox has already expired every session that came in through a Lenovo ID and now asks for your Dropbox password before a Lenovo ID login works.
  2. Check your Dropbox security page for devices and linked apps you do not recognise, and remove them. Look at “connected accounts” or SSO options and disconnect any identity provider you did not choose.
  3. Turn on two-factor authentication on Dropbox even if you were not notified. Dropbox said none of the 5,000 affected accounts had it on.
  4. Think about what was in the folder. If you keep scans of ID documents, financial paperwork or password lists in cloud storage, treat those as potentially exposed: consider a credit freeze at the three US bureaus (Equifax, Experian, TransUnion — each is free to place and lift), and rotate any credentials stored in those files.
  5. Do not click the next “Dropbox security alert” — go to dropbox.com yourself and check the account directly. Real notices from Dropbox will be reflected inside your account.
  6. Encrypt sensitive files before uploading them anywhere. One affected user reported that the one file the attacker tried to open was one he had encrypted locally first. Cloud storage is convenient; it is not a safe.

How OptMsg Helps

OptMsg is an opt-in email service: only people you approve can reach your inbox, and everyone else goes to Trash, where mail is auto-deleted after 30 days. That is the patent-pending opt-in technology in one sentence.

Be clear about what that does and does not change here. OptMsg had nothing to do with Dropbox’s or Lenovo’s systems and would not have changed what happened inside them. If your files were downloaded, no email service can bring them back.

What an opt-in inbox changes is the part that comes next. This story is going to be used as bait, and the fake “confirm your Dropbox account” message from a sender you have not approved lands in Trash rather than sitting in your Inbox next to real mail, looking like real mail.

There is a second, quieter lesson in this breach, and it is about the account at the centre of everything: your email. The attackers here got in by convincing a third party that they owned an email address. Your email is how most accounts get reset. Keep that door shut and the rest stay shut with it — which is why an OptMsg account has no password at all, so a password stolen from another site can’t open your inbox.

If the part of this that worries you is a convincing fake landing where you trust things to be real, that is what an opt-in inbox is built for. You can create an OptMsg account and see how your own inbox behaves, or read more about how OptMsg approaches account security.

Create Your Account

Sources

No standalone Dropbox disclosure page is linked above because none had been published at the time of writing. Dropbox’s statement exists as an email to affected users and as on-record comments to Reuters and Bloomberg.

Scroll to Top