A Dropbox account breach affected about 5,000 users after attackers exploited a Lenovo ID authentication flaw to access accounts using only victims’ email addresses.
Dropbox said the activity ran from August 4 to August 21. The attackers created Lenovo IDs using victims’ email addresses, then linked those identities to existing Dropbox accounts.
Lenovo ID flaw bypassed password sign-ins
Dropbox lets customers use verified Lenovo IDs as an identity provider for account sign-ins.
Attackers abused a flaw that let them register Lenovo IDs for email addresses without proving that they controlled the inboxes. They could then use the newly created Lenovo identity to start a Dropbox session.
The attack did not require attackers to steal passwords, defeat encryption or compromise Dropbox’s storage systems.
Victims did not need to have an existing Lenovo ID. Most of the affected Dropbox accounts did not use two-factor authentication.
Files may have been viewed or downloaded
Dropbox said that roughly one-third of the compromised accounts show signs that attackers viewed or downloaded files.
The company cannot fully determine the impact from activity logs alone. Some affected users may have stored sensitive documents, including tax files, financial records or identity information, in their accounts.
Users began reporting unexpected Dropbox sign-in alerts in mid-August. Some also received Lenovo verification codes that they had not requested.
In several cases, attackers created unauthorised Lenovo profiles with victims’ email addresses and throwaway names.
Dropbox resets affected account connections
Dropbox said it expired sessions that used Lenovo IDs and removed the connection between Lenovo and affected Dropbox accounts.
The company also changed its login process. Users must now enter their Dropbox password before signing in with a Lenovo ID.
Dropbox advises affected users to change their Dropbox passwords and email passwords. It also recommends enabling two-step verification to help protect accounts from further unauthorised access.


0 responses to “Dropbox Account Breach Affects 5,000 Users Through Lenovo ID Flaw”