AI News Feed
Market watch
Cybersecurity

Over 5,000 Dropbox Accounts Compromised via Lenovo ID Flaw

Roughly 5,000 Dropbox accounts were breached via a Lenovo email verification flaw, Dropbox said.

The breach exploited Dropbox's integration with Lenovo as an identity provider. Dropbox explained that a problem with Lenovo's email verification allowed an outside party to register a Lenovo ID using the victim's email address and then log into the associated Dropbox account. The attackers needed only email addresses to carry out the scheme.

Dropbox said most of the affected accounts did not have two-factor authentication (2FA) enabled, and in about one-third of the cases there was evidence that stored documents had been viewed or downloaded.

The vulnerability has been fixed. Dropbox said it promptly expired all sessions logged in through Lenovo IDs and terminated all links between Lenovo and Dropbox accounts. It now requires users to enter a password when logging in through a Lenovo ID. The company is urging affected users to change their passwords, enable two-step verification, and update the passwords for their email accounts.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said that every compromised account lacked multi-factor authentication. He described the combination of an unreviewed third-party authentication pathway and accounts without MFA as an open invitation, and advised organizations and individuals to periodically audit which third-party services have authentication access to their accounts.