{
  "story_id": "dc31f66f565ddba73ef17a9e8eed3080",
  "desk": "drm3",
  "revision": 1,
  "published_at": "2026-09-01T20:01:05.000Z",
  "content_hash": "ea0273ae8d816e6a9dfedeb1a9040c91550bf08a31037711a08189bbe8458826",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "Dropbox Users Hit by Lenovo ID Authentication Flaw",
    "dek": "Dropbox notified 5,000 users of unauthorized access via a Lenovo ID authentication vulnerability.",
    "prose": "Dropbox notified users that unauthorized parties accessed their accounts between August 4 and August 21, 2026, through an authentication flaw involving Lenovo IDs. [^1]\n\nThe root cause of the breach was identified as a lack of authentication when attackers created a single sign-on option through a third-party company, specifically Lenovo. [^2]\n\nAn issue with Lenovo's email verification process allowed unauthorized parties to register Lenovo IDs using other people's email addresses and then use those identities to access associated Dropbox accounts. [^3]\n\nDropbox spokespersons told Decrypt that approximately 5,000 Dropbox accounts were impacted by the unauthorized access. [^4]\n\nDropbox stated that the incident exploited the way the company handled single sign-on (SSO) through Lenovo IDs. [^5]",
    "cited": "[{\"statement\":\"Dropbox notified users that unauthorized parties accessed their accounts between August 4 and August 21, 2026, through an authentication flaw involving Lenovo IDs.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T20:01:05.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"The root cause of the breach was identified as a lack of authentication when attackers created a single sign-on option through a third-party company, specifically Lenovo.\",\"source\":\"9to5Mac\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T12:54:49.000Z\",\"publisher_count\":1,\"sources\":[\"9to5Mac\"]},{\"statement\":\"An issue with Lenovo's email verification process allowed unauthorized parties to register Lenovo IDs using other people's email addresses and then use those identities to access associated Dropbox accounts.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T20:01:05.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"Dropbox spokespersons told Decrypt that approximately 5,000 Dropbox accounts were impacted by the unauthorized access.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T20:01:05.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]},{\"statement\":\"Dropbox stated that the incident exploited the way the company handled single sign-on (SSO) through Lenovo IDs.\",\"source\":\"Decrypt\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T20:01:05.000Z\",\"publisher_count\":1,\"sources\":[\"Decrypt\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "280632826d7c79e81661e6fe905367b6",
      "thread_id": "b22b2a935c77201ea18c628621dcf373",
      "thread_label": "Yoni Levy",
      "novelty": "UPDATE",
      "content_hash": "163d0804b61e10b7f10ea4252260716178a25e8d4e9db0964621c24ae1da11b3",
      "last_published_at": "2026-09-01T20:01:05.000Z",
      "read_receipt": {
        "slice_hash": "0fa9f6bf3dba25d238384a3347cb1dd0000513ec909de93440dff3f48b8edbfe",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDFUMTk6NDE6MzYuMDAwMDAwWiIsImlkIjoiMDM4NDgxNTEyMzViOTI1YmVlZmVkMTA0NGFiNDQxNWUiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDFUMjA6MTI6MDAuMDAwMDAwWiIsImlkIjoiYjExNzQ4NWUwOGQ1ODUwNGY0OTgzMzM0M2NiMTZhY2IiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 12017721,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "xXx0tBesFyw1LYKFQjnO710iUK1E54mK7M1YM1vG-8GeKpiKXJaPIrB6H_BWTh9UHvegrFM5ImaCNOvOojtXDQ",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-02T22:16:01.298Z"
  },
  "cited_facts": [
    {
      "statement": "Dropbox notified users that unauthorized parties accessed their accounts between August 4 and August 21, 2026, through an authentication flaw involving Lenovo IDs.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T20:01:05.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "The root cause of the breach was identified as a lack of authentication when attackers created a single sign-on option through a third-party company, specifically Lenovo.",
      "source": "9to5Mac",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T12:54:49.000Z",
      "publisher_count": 1,
      "sources": [
        "9to5Mac"
      ]
    },
    {
      "statement": "An issue with Lenovo's email verification process allowed unauthorized parties to register Lenovo IDs using other people's email addresses and then use those identities to access associated Dropbox accounts.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T20:01:05.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "Dropbox spokespersons told Decrypt that approximately 5,000 Dropbox accounts were impacted by the unauthorized access.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T20:01:05.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    },
    {
      "statement": "Dropbox stated that the incident exploited the way the company handled single sign-on (SSO) through Lenovo IDs.",
      "source": "Decrypt",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T20:01:05.000Z",
      "publisher_count": 1,
      "sources": [
        "Decrypt"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}