Someone registered a Lenovo ID with your email, then used it to open your Dropbox. No password required
2026-09-05Security
A weakness in Lenovo's email verification let an attacker claim an address they did not control. Dropbox's account linking accepted Lenovo's word for it without asking for the Dropbox login. About 5,000 accounts were reachable that way between 4 and 21 August.