Identity

Hackers compromise 5,000 Dropbox accounts using Lenovo ID flaw

Dropbox mobile icon app on screen smartphone iPhone. Dropbox is file hosting company Dropbox Inc.

Per Tech Radar, hackers exploited a vulnerability in Lenovo's email verification process to gain unauthorized access to approximately 5,000 Dropbox accounts. The attackers created Lenovo IDs using victims' email addresses, bypassing standard login procedures.

The breach, which occurred between August 4 and August 21, allowed attackers to access Dropbox accounts by registering Lenovo IDs with the victims' email addresses. This method circumvented Dropbox's usual login requirements. The impact was exacerbated by the fact that most compromised accounts lacked two-factor authentication (2FA). In about a third of these accounts, evidence suggests that stored documents were viewed or downloaded. Dropbox has since terminated the integration with Lenovo IDs, expired all active sessions linked to Lenovo IDs, and urged affected users to change their passwords and enable 2FA.

Cybersecurity experts recommended users regularly audit third-party authentication access to their accounts and ensure multi-factor authentication is enabled to prevent similar incidents.

Source: Tech Radar

You can skip this ad in 5 seconds