V-Help
← All news
Security

Dropbox Reports Account Breaches via Lenovo Email Verification Flaw

Dropbox Reports Account Breaches via Lenovo Email Verification Flaw

Photo: BleepingComputer

Quick answer

Attackers breached approximately 5,000 Dropbox accounts by exploiting a flaw in Lenovo’s email verification system, enabling unauthorized access without passwords.

Dropbox has warned users of unauthorized access to their accounts, which was made possible by a vulnerability in Lenovo’s email verification system. Attackers registered fake Lenovo IDs on victims' email addresses and used them to log into linked Dropbox accounts without needing the Dropbox password.

The incident affected users who did not have Lenovo accounts but relied on Lenovo Identity Provider Services for Dropbox authentication. Dropbox attributed the issue to an error in Lenovo’s email verification process, which allowed attackers to confirm control over email addresses without additional checks.

According to Reuters, the attack impacted around 5,000 accounts, with unauthorized access occurring between August 4 and 21. Some users reported suspicious login attempts two weeks before the breach was detected. In response, Dropbox terminated all sessions authenticated via Lenovo ID and introduced a new requirement: users must now enter their Dropbox password when logging in through Lenovo ID.

Lenovo confirmed the vulnerability stemmed from an outdated integration between Lenovo ID and Dropbox. While the issue has been resolved, the investigation into the incident is ongoing. Users with Lenovo accounts were not affected by this vulnerability.

Common questions

How did attackers gain access to Dropbox accounts?
Hackers exploited a vulnerability in Lenovo’s email verification process to register fake Lenovo IDs on victims' email addresses. These IDs were then used to bypass password requirements and access Dropbox accounts.
How many Dropbox accounts were compromised?
According to Reuters, nearly 5,000 accounts were breached, with attackers viewing and downloading some users' data.
What steps did Dropbox take to mitigate the issue?
Dropbox terminated all active sessions authenticated via Lenovo ID and enforced mandatory password entry for Dropbox accounts when logging in through Lenovo ID.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer