An old forgotten Lenovo portal exposes 5,000 Dropbox accounts to attackers - the debt of federated identity

In this saga : Attaques supply chain dans l'open source· Episode 2/2

Cybersecurity Sep 3, 2026Add to bookmarks

An old forgotten Lenovo portal exposes 5,000 Dropbox accounts to attackers - the debt of federated identity

The Register documents how an old Lenovo login system, left in place after a forgotten SSO integration, allowed access to 5,000 Dropbox accounts. A textbook case of federated identity debt in supply chains.

The Facts

The Register reported on September 2, 2026, that an old Lenovo login system—a remnant of a once-active SSO (Single Sign-On) partnership that was no longer being maintained—was exploited to access approximately 5,000 Dropbox accounts.

The attack vector: a Lenovo authentication service, historically federated with Dropbox to allow users of Lenovo hardware (or customers of a partner program) to log into Dropbox using their Lenovo credentials, remained in production even after the commercial partnership had gone dormant. With no active oversight, leaked credentials from past breaches allowed attackers to exploit this forgotten gateway to reach Dropbox.

Who Is Affected

  • Approximately 5,000 Dropbox account holders who had once linked their accounts to a Lenovo ID—sometimes years ago, often long forgotten.
  • Dropbox itself, whose reputation as a consumer-focused SaaS provider took a hit—the flaw wasn’t in Dropbox but in a third-party integration it still honored.
  • Any SaaS provider that has retained historical SSO integrations—the pattern is reproducible far beyond Lenovo/Dropbox.

Why This Matters

We’ve been tracking supply chain attacks via compromised open-source libraries (XZ Utils, npm Vite, GoCaracal). This incident expands the scope: the supply chain isn’t just about code—it’s also about identity services. A forgotten backdoor is as dangerous as one intentionally planted.

Three key takeaways:

  1. Federated identity debt is invisible. An SSO partnership can be set up in hours and rarely documented for decommissioning. Five years later, no one remembers it exists—but the authentication code is still running.
  2. SSO becomes a lateral movement vector between unrelated services. A leaked Lenovo ID shouldn’t grant access to Dropbox—but if the integration exists and isn’t monitored, it still works.
  3. The cost of decommissioning integrations is underestimated. Cleanly exiting a third-party SSO requires: revoking tokens, disabling callbacks, notifying users, and migrating accounts to native auth. It’s never prioritized.

What to Do Now

For SaaS platform administrators:

  • Audit all SSO integrations—which are active, which are dormant, and which are old commercial partnerships no one has unplugged?
  • Set an expiration date for every SSO integration created. If not explicitly renewed, it’s revoked.
  • Log connections by IdP (Identity Provider): a sudden spike in logins via a dormant IdP is an immediate red flag.

For end users:

  • Inventory linked connections in the security settings of your SaaS accounts (Dropbox, Google, Microsoft, etc.). Revoke anything you no longer use.
  • Enable 2FA everywhere—it’s the barrier that prevents a leaked ID from being enough.
  • Change passwords for affected services if you ever linked your account to a Lenovo ID (or any other hardware manufacturer).
5,000 accounts, one forgotten door

5,000 Dropbox accounts compromised via a Lenovo authentication system no one was monitoring. The identity supply chain is as fragile as the code supply chain.

Bottom line: The identity supply chain deserves the same level of scrutiny as the code supply chain. Every third-party SSO integration is a potential backdoor if it outlives its purpose. Audit, expire, monitor—or attackers will do it for you.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

22 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
The saga

Attaques supply chain dans l'open source

  1. 1XZ Utils and "Half a Second": Autopsy of the supply chain attack that nearly compromised the Internet31/08/2026
  2. 2An old forgotten Lenovo portal exposes 5,000 Dropbox accounts to attackers - the debt of federated identity03/09/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information