It begins, as these things now begin, with a convenience. One company agrees to vouch for you at the gate of another company: a keyboard tap saved, a password never typed. What is quietly surrendered in the bargain is a share of your account’s security, handed to a vendor you never chose and may never have heard of. Dropbox has just learned the price of that arrangement. The cloud-storage company is warning roughly 5,000 customers that intruders reached their accounts through Dropbox’s identity federation with Lenovo, the personal-computer maker — and that no Dropbox password was ever asked for, or needed.

The breach was first reported by BleepingComputer, a security-news outlet, which traced the intrusion to a flaw in how Lenovo verifies who owns an email address.

The door left off the map

The mechanism was simple enough to be embarrassing. Dropbox allows people to sign in through Lenovo Identity Provider Services, one of several single sign-on options bound to Lenovo’s account system. Anyone holding a verified Lenovo ID could reach the Dropbox account attached to that email address. The attacker exploited a bug in Lenovo’s confirmation process and used a fraudulent Lenovo ID to walk directly into a victim’s Dropbox. Dropbox trusted Lenovo’s assertion and never asked the account holder to confirm anything through an existing login. Some of the roughly 5,000 people exposed had never held a Lenovo account at all.

There is a parable here about delegated trust, and it deserves stating as reflection, not as finding: a fortress may be perfectly guarded at its own walls and still be entered through an ally’s rotten gate. The bug lived at Lenovo. But its only visible symptom surfaced inside Dropbox, on Dropbox’s own login screen.

A user who goes by xaphod noticed something that should not have existed — a new “Continue with SSO” option on the Dropbox login page, despite never having created a Lenovo ID. That small, anomalous button was the warning sign, sitting in plain sight days before anyone traced it back to its source. A password-free account takeover, with no Dropbox credential involved anywhere in the chain.

Lenovo described the issue as a legacy integration between Lenovo ID and Dropbox, and said its own customers were not affected. The word legacy does quiet work in such statements — it suggests the past, a thing inherited rather than chosen. But the link between the two companies had gone unmapped for years before this breach surfaced it. A trust link nobody wrote down is a trust link nobody was watching.

Closing the gate, counting the doors

Lenovo has now closed the integration. Dropbox has expired every session that entered through a Lenovo ID and now requires the Dropbox password before any Lenovo ID login can proceed. Both fixes address the specific wound. Neither touches the underlying condition: any company running federated single sign-on carries the same exposure, because login security has been partly contracted out to an outside identity provider.

The lessons drawn by security practitioners are procedural. Inventory every federated login path into each tenant — Dropbox’s link to Lenovo went unmapped for years. And confirm ownership locally before honoring a partner’s assertion: checking a partner’s word against the account’s own login is cheap, while delegated identity keeps becoming a leading path into the enterprise.

The convenience that let a Lenovo ID open a Dropbox account has not gone away; it is the architecture of the modern login, replicated across countless pairings of companies. What this episode adds is the demonstration that identity federation quietly made Lenovo a part of Dropbox’s login security — and that the attacker worked that out before Dropbox did.