third-party identity risks. A recent incident involved Dropbox and Lenovo ID following a vulnerability in the latter’s authentication system that allowed a hacker to access approximately 5,000 Dropbox accounts.

According to Dropbox, unauthorized access occurred between August 4 and 21, 2026. In less than one-third of cases, files within the accounts were viewed or downloaded. The attack did not directly target Dropbox systems but exploited a flaw in Lenovo ID’s authentication system through the existing link between the two services.
third-party identity risks: why it matters
The vulnerability concerned email address verification: an unauthorized party could register a Lenovo ID associated with another user’s email and, through that account, access the corresponding Dropbox account. The situation was aggravated by the fact that the compromised accounts did not use multi-factor authentication.
Dropbox subsequently terminated authenticated sessions via Lenovo ID, disabling the link between the two services and introducing additional access requirements.
GDPR Implications
From a legal perspective, the incident raises questions about security in personal data processing. The GDPR requires data controllers and processors to adopt technical and organizational measures appropriate to the risk, considering also the systems’ ability to ensure data confidentiality, integrity, and availability.
A breach does not necessarily consist of database theft: unauthorized access to an account containing personal data can constitute a violation under the GDPR. Companies must therefore assess notification obligations to the supervisory authority within 72 hours of discovering the breach and, in more serious cases, communicate it to affected individuals.
The case also highlights risks related to the security of integrations with third parties. Relying on an identity provider or external service does not automatically transfer security responsibility; using authentication systems requires risk assessment regarding the technological chain and user identity verification methods.
Key Security Measures
What changes and what are the effects
The Dropbox-Lenovo episode underscores the importance of digital identity management in cybersecurity. A first step involves inventorying third-party integrations and authentication systems, verifying which applications can access corporate systems, with which credentials, and through which mechanisms.
Particular attention should be paid to legacy integrations, implemented in the past and still active despite their usage becoming marginal. It is also advisable to adopt multi-factor authentication (MFA) where possible, adding an extra layer of protection in case of credential or external authentication system compromise.
At the organizational and contractual level, it is necessary to verify services provided by third parties, especially ICT and cloud services, defining responsibilities, security measures, incident management procedures, and communication obligations. Supplier and external service security must be an integral part of overall corporate security management.
Finally, procedures must be established to promptly identify anomalous access and incidents, defining responsibilities, intervention methods, and criteria for involving the IT manager, DPO, legal consultants, and, if necessary, competent authorities.
The incident involving Dropbox and Lenovo ID demonstrates that in today’s digital ecosystem, an organization’s vulnerability may reside outside its systems. Security cannot be assessed solely by checking corporate server protection; it is necessary to consider who can access systems, with which tools, which third parties are considered trustworthy, and whether such relationships are still necessary and secure. Technological integrations must be periodically mapped, evaluated, and eliminated when no longer needed. Security is not a one-time requirement but a continuous process that must accompany the entire lifecycle of systems and supplier relationships.
Source and further reading on third-party identity risks: original article.
* Content created with the assistance of artificial intelligence systems.
Hardware Ready Ready to Bench?