About 5,000 Dropbox accounts were opened with a Lenovo ID nobody had created
Here is a breach with no stolen password in it. Between 4 and 21 August, someone registered Lenovo IDs using other people's email addresses, then used "Continue with SSO" on the Dropbox login page to walk into the Dropbox account attached to that same address. Lenovo's email verification never properly checked that the person signing up owned the address. Dropbox accepted the resulting Lenovo ID as proof of identity without asking for a Dropbox password. Around 5,000 accounts were reached, and files were downloaded from roughly 1,500 of them.
Notification emails started landing around 31 August, which is how most people found out. Several described the same unsettling detail beforehand: the Dropbox sign-in page suddenly offering them a single sign-on option for a Lenovo account they had never made.
Both companies have closed it. Dropbox expired every session that had been authenticated through a Lenovo ID, unlinked those IDs from accounts, and now demands your Dropbox password before a Lenovo login gets you anywhere. Lenovo fixed the verification gap.
The part worth carrying away is which accounts survived. Anyone with Dropbox two-factor authentication turned on was not affected, because the second step stood between the attacker and the files no matter how convincing the login looked. That is the argument for 2FA in one sentence: it keeps working when the login itself has been quietly broken. Tendvane's Privacy and accounts check lists the accounts signed in on your PC and where your files are syncing, which is a sensible thing to read before deciding which ones deserve a second factor first.