The interesting part is that it came through a legacy Lenovo ID authentication flow, not some crazy “encryption got broken” scenario.
Makes you wonder where the real weak point in cloud storage usually is — encryption, login, or third-party integrations?


If you aren’t the only one with the keys, it’s basically unencrypted. Bake in your own encryption (rclone, cryptomator, etc), or treat it as unencrypted.