Per Tech Radar, hackers exploited a vulnerability in Lenovo's email verification process to gain unauthorized access to approximately 5,000 Dropbox accounts. The attackers created Lenovo IDs using victims' email addresses, bypassing standard login procedures.The breach, which occurred between August 4 and August 21, allowed attackers to access Dropbox accounts by registering Lenovo IDs with the victims' email addresses. This method circumvented Dropbox's usual login requirements. The impact was exacerbated by the fact that most compromised accounts lacked two-factor authentication (2FA). In about a third of these accounts, evidence suggests that stored documents were viewed or downloaded. Dropbox has since terminated the integration with Lenovo IDs, expired all active sessions linked to Lenovo IDs, and urged affected users to change their passwords and enable 2FA.Cybersecurity experts recommended users regularly audit third-party authentication access to their accounts and ensure multi-factor authentication is enabled to prevent similar incidents.Source: Tech Radar
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds

