Multiple Dropbox users have been emailed by the cloud storage company to advise them that a security breach saw unauthorised access to their account. Update: the company has said that about 5,000 accounts were compromised, with files downloaded from around 1,500 of them.

The root cause appears to be a lack of authentication by Dropbox when attackers created a single sign-on option through a third-party company …

Developer Yoni Levy posted a copy of the email he received on X.

We are writing to let you know that we’ve observed unauthorized access to your Dropbox account between August 4 and August 21, 2026. While our logs show no evidence that your files were viewed or downloaded, we want to share with you what happened, what we are doing about it, and what additional steps you can take.

Other Dropbox users reported receiving the same email in which the company said it resulted from a problem with a single sign-on (SSO) option using Lenovo IDs.