Dropbox is notifying some users that their accounts were accessed after an unauthorized party exploited a flaw in Lenovo’s email verification process, according to BleepingComputer. The issue centered on Lenovo Identity Provider Services, which Dropbox used as part of its authentication infrastructure for signing in with verified Lenovo IDs. BleepingComputer reports that some affected Dropbox users did not have Lenovo accounts. According to the notices described by the outlet, the flaw allowed an unauthorized party to register a Lenovo ID using a Dropbox user’s email address, then use that Lenovo ID to access the Dropbox account associated with the same email address. The reported failure was in the trust boundary between the two identity systems. Dropbox’s login flow accepted Lenovo’s assertion that the Lenovo ID controlled the email address, without requiring the person using that route to confirm access through the existing Dropbox password path, according to BleepingComputer’s account of the incident. Dropbox determined that the unauthorized access took place between August 4 and August 21, BleepingComputer reports. Some users also reported earlier suspicious Dropbox sign-in notifications and said they changed passwords and enabled two-factor authentication after seeing the activity. Lenovo told BleepingComputer the issue was tied to a legacy integration between Lenovo ID and Dropbox that could be used to improperly authenticate certain Dropbox accounts. Lenovo also said Dropbox and Lenovo worked together to mitigate the risk, and that Lenovo customers were not affected by the issue. Dropbox’s response, according to BleepingComputer, included expiring all sessions authenticated through Lenovo IDs. The company also added a new requirement that users enter their Dropbox account password when attempting to use Lenovo ID authentication. Reuters, as cited by BleepingComputer, reported that approximately 5,000 accounts were accessed and that the hacker viewed and downloaded content from some users. BleepingComputer said it had contacted Dropbox for more information and had not received a response as of publication. Who benefits: Users benefit from Dropbox’s added password requirement for Lenovo ID authentication, assuming it blocks the same login path. Security teams also get a concrete example to review similar identity-provider integrations. Who's exposed: Dropbox users whose accounts were accessed are directly exposed, especially where content was viewed or downloaded, according to the Reuters detail cited by BleepingComputer. Organizations using third-party login paths face comparable review risk if identity linking depends on another provider’s email verification.