Dropbox says about 5,000 accounts compromised in August hack
Dropbox said unauthorised access affected accounts linked to Lenovo IDs without two-factor authentication, prompting it to terminate all Lenovo ID-authenticated sessions.
Dropbox disclosed on Tuesday that approximately 5,000 accounts were compromised in August. The unauthorized access allowed hackers to view and download content stored on the cloud-storage platform, with some users receiving a notification from the company on Monday. The breach came to light after Bloomberg News reported on the incident earlier in the day. Hackers accessed files in less than a third of the compromised accounts, according to Dropbox.
The company identified unauthorized access affecting accounts linked to a Lenovo ID that lacked two-factor authentication. In response, Dropbox terminated all sessions authenticated through the Lenovo ID. The company removed any connections between Lenovo IDs and Dropbox accounts and updated its systems to require users to enter their Dropbox password before accessing an account through Lenovo.
Dropbox reported the incident to data protection regulators. Lenovo identified a legacy integration between the Lenovo ID and Dropbox that could be exploited to improperly authenticate certain Dropbox accounts. The company stated that its own customers were not affected, and an investigation was underway.
Written by urgent.news from Free Malaysia Today's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Dropbox says about 5,000 accounts compromised in August hack freemalaysiatoday.com
- Dropbox says about 5,000 accounts compromised in August hack channelnewsasia.com