Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

← Back to the feed

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

The Register · 2 hours ago

Dropbox has warned roughly 5,000 users that attackers hijacked their accounts by exploiting a legacy login integration with Lenovo. The flaw stemmed from a weakness in Lenovo's email verification process, which let attackers register Lenovo IDs using victims' Dropbox email addresses and then use those IDs to log straight into the corresponding Dropbox accounts without ever needing the actual Dropbox password. The incident highlights the risks of third-party login integrations and the importance of two-factor authentication, since none of the affected accounts had it enabled.

The breach ran from 4 to 21 August, and Dropbox says attackers accessed files in fewer than a third of the compromised accounts. One affected user, Bitcoin security expert Jameson Lopp, said attackers only tried to open a single locally encrypted file. Dropbox has since expired all sessions linked to Lenovo IDs, severed the integration entirely, and is urging affected users to reset their Dropbox and email passwords and turn on 2FA. Lenovo says its own systems and customers were not affected and that it is still investigating.

  • Legacy Lenovo login flaw let attackers into ~5,000 Dropbox accounts.
  • Breach lasted 4–21 August; no victims had 2FA enabled.
  • Dropbox severed the Lenovo integration and urges password resets.

Software

Read the full article at the source →