Urgent.News

What's breaking now, across thousands of outlets.

Tech

Dropbox says about 5,000 accounts compromised in August hack

Dropbox says about 5,000 accounts compromised in August hack

Dropbox disclosed on Tuesday that approximately 5,000 user accounts were compromised in August, as hackers gained unauthorized access to view and download content stored within the cloud storage platform. The company announced this discovery following a report by Bloomberg News on the incident earlier in the day.

Users began receiving emails from Dropbox on Monday, informing them that their accounts had been accessed without permission between August 4 and August 21. According to Dropbox, hackers had only accessed files in fewer than one-third of the affected accounts. The company reported that its stock experienced a decline of around 2.4% in extended trading on Tuesday.

In response to the breach, Dropbox identified unauthorized access linked to a Lenovo ID that lacked two-factor authentication, leading the company to terminate all sessions authenticated through the Lenovo ID. The company has since severed any connections between Lenovo IDs and Dropbox accounts, implementing system changes requiring users to input their Dropbox password before accessing an account via Lenovo.

Dropbox reported the incident to data protection authorities. Lenovo recognized the underlying vulnerability as a "legacy integration" between its Lenovo ID and Dropbox. The company confirmed that its own customers were not impacted and emphasized that an investigation into the matter is currently underway.

Written by urgent.news from MyJoyOnline Ghana's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at finance.yahoo.com →

More in Tech

Phone Login Admin Operations — Exact Lookup, Profile Updates, and Controlled Deletion

Short answer: model every admin action as a validated, auditable, recoverable state transition; use the user ID after lookup, and put deletion behind an explicit policy check.

  • Admin actions should be distinct, auditable, reversible state transitions
  • Separate commands for lookup, update, and delete with authorization checks
  • Example from media app implements commands with audit records

More from Wednesday 2 September →