Some Dropbox users received an email from the company on Monday notifying them that their accounts have been accessed without authorization between August 4 and August 21, Dropbox confirmed after Bloomberg News reported the hack earlier in the day.

Attackers reportedly registered Lenovo IDs using victims’ email addresses, allowing them to sign into existing Dropbox accounts without their passwords.

Dropbox says it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled