This hack of 5000 Dropbox accounts was not sophisticated. It did not rely upon advanced malware, or exploit a complex zero-day vulnerability. This was simply the case of an attacker finding a glaring loophole in the security of one company's identity system, and that it was being implicitly trusted by another's.
Source: https://www.bitdefender.com/en-us/blog/hotforsecurity/lenovo-login-system-hackers-dropbox