Dropbox breach compromises 5,000 accounts through Lenovo ID loophole
SAN FRANCISCO, Sept 2 — Online file storage and sharing service Dropbox accounts were compromised last month after...
SAN FRANCISCO, Sep 2 — Unauthorized access to around 5,000 Dropbox accounts occurred in August, according to reports from Reuters and Bloomberg. The breach transpired between August 4 and August 21, during which hackers viewed and downloaded files. The affected accounts lacked multi-factor authentication and were connected to Lenovo IDs.
The authentication system flaw was identified in Lenovo's email verification process. Hackers exploited this vulnerability to create Lenovo IDs through the email addresses of unsuspecting Dropbox users who hadn't registered for the service. Dropbox promptly terminated all Lenovo ID-authenticated sessions, severed the connections between the two platforms, and enforced password entry for account access through Lenovo.
The company notified regulators and affected users upon discovering the breach. Lenovo disclosed a "legacy integration" with Dropbox that could enable unauthorized authentication of certain accounts. The company affirmed that no other customer data was compromised and that it is collaborating with Dropbox to alleviate the risk while the investigation proceeds.
Written by urgent.news from Malay Mail's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.