Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
A bug in Lenovo's ID verification system made it possible to access Dropbox accounts, but the bug has since been fixed.
A security flaw in Lenovo's email verification process allowed hackers to hijack around 5,000 Dropbox accounts. All that the criminals needed was the victims' email addresses. The attack occurred between August 4 and 21, and most compromised accounts lacked two-factor authentication (2FA). Dropbox ended Lenovo ID logins, expired sessions, and urged users to change their passwords and enable 2FA.
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, emphasized that the vulnerability highlights the importance of auditing third-party services that have authentication access to personal accounts.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.