Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Cloud storage biz severs old integration and urges victims to reset credentials
Dropbox has alerted approximately 5,000 users that their accounts were compromised due to an exploit in a legacy Lenovo login integration. The cloud storage company attributed the breach to an issue with Lenovo's email verification process, which allowed attackers to register Lenovo IDs using the email addresses of Dropbox users and subsequently gain access to their accounts. This vulnerability persisted from August 4 to August 21.
According to Dropbox, attackers accessed files belonging to fewer than a third of the affected users. Bitcoin security expert Jameson Lopp, co-founder of Casa, reported that a malicious party attempted to access one of his encrypted files, titled "IMPORTANT.rtf," which had been uploaded to Dropbox prior to encryption.
Dropbox disclosed the extent of the breach to Reuters and stated that none of the affected accounts had two-factor authentication (2FA) enabled. Following the discovery of the attack, the company promptly terminated all sessions logged in through Lenovo IDs and severed any connection between the affected accounts and Lenovo. In its email to users, Dropbox advised them to change their Dropbox and personal email passwords, as well as enable 2FA.
Lenovo informed Reuters that its customers were not affected, and that its investigation was ongoing. The Register sought additional information from both Dropbox and Lenovo.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Legacy Lenovo login opens 5,000 Dropbox accounts to attackers theregister.com