Dropbox Breach Affects 5,000 Accounts After SSO Authentication Failure
Dropbox disclosed a security breach affecting about 5,000 accounts after attackers exploited an authentication flaw in its Lenovo SSO integration, with files downloaded from roughly 1,500 accounts.
The email initially stated that logs showed no evidence that files were viewed or downloaded, but the company subsequently updated its disclosure to confirm file downloads from a subset of accounts. Dropbox attributed the breach to a problem with a single sign-on (SSO) option that uses Lenovo IDs, saying an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using a victim's email address and then log into the associated Dropbox account.
Security blog The CyberSec Guru reported that the larger issue lay with Dropbox, which did not require users to verify a new SSO option with their existing login before it became active. 9to5Mac's analysis called this an "egregious fault," noting that authenticating the linked identity would have prevented the attack. The attack flow involved the unauthorized party registering a rogue Lenovo ID, bypassing or exploiting a missing verification step, and then selecting "Continue with Lenovo" on Dropbox. Lenovo's authorization server issued a token matching the victim's email, and Dropbox linked the token to the existing account and created a session without a password prompt or consent request.
Dropbox said it has fixed the underlying flaw and expired all sessions previously authenticated through a Lenovo ID.