All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Dropbox Accounts Breached Via Lenovo ID Authentication Flaw

Created at 1 Sep · 8:07 PM1 source↑ Market-relevant
IN SHORT

Dropbox reported that hackers accessed approximately 5,000 user accounts between August 4 and August 21 by exploiting an authentication flaw in Lenovo ID. The attackers registered Lenovo IDs with other people's email addresses to access linked Dropbox accounts, though Dropbox stated no evidence of file viewing or downloading was found for most affected users.

Key Numbers

5,000Dropbox accounts impacted
August 4 - August 21Unauthorized access window

Who's Involved

Dropbox
cloud storage service that experienced a security breach
Lenovo ID
authentication service exploited in the breach
Yoni Levy
affected Dropbox user who posted screenshots of the notification
Dropbox Accounts Breached Via Lenovo ID Authentication Flaw

↳ Why This Matters

The incident highlights vulnerabilities in single sign-on systems and the importance of robust multi-factor authentication, as accounts without it were susceptible to unauthorized access through third-party authentication flaws.

Key facts

  • Dropbox accounts were accessed without authorization between August 4 and August 21.
  • The breach exploited an issue with Lenovo's email verification process for single sign-on.
  • Attackers registered Lenovo IDs using other people's email addresses to access linked Dropbox accounts.
  • Approximately 5,000 Dropbox accounts were impacted.
  • Less than a third of affected accounts had files viewed or downloaded, according to Dropbox.
  • Dropbox has updated its authentication process related to Lenovo IDs.

Dropbox has alerted users to unauthorized access of their accounts, which occurred between August 4 and August 21. The security incident was reportedly caused by an authentication flaw involving Lenovo ID, the single sign-on service used by some Dropbox users. Attackers exploited an issue with Lenovo's email verification process, allowing them to register Lenovo IDs with email addresses belonging to other individuals. These newly created Lenovo IDs were then used to log into the corresponding Dropbox accounts without needing the user's Dropbox password or access to their email inbox.

Dropbox stated that approximately 5,000 accounts were impacted. The company emphasized that its investigation found no evidence that files were viewed or downloaded for the majority of these accounts. However, less than a third of the affected accounts did have files viewed or downloaded. Dropbox has directly emailed all impacted users and has since modified its authentication procedures related to Lenovo IDs to prevent future exploitation.

One affected user, developer Yoni Levy, shared screenshots of the notification on X, detailing a login to his account via Chrome on Windows from near Canary Wharf, England, on August 18. Levy stated he had no Lenovo account and had never been to the UK.

Frequently asked questions

The breach was caused by an authentication flaw in Lenovo ID, where attackers could register Lenovo IDs with other people's email addresses and use them to access linked Dropbox accounts.

Approximately 5,000 Dropbox accounts were impacted by the unauthorized access.

Dropbox stated that for most affected accounts, there was no evidence of files being viewed or downloaded. Less than a third of impacted accounts had files viewed or downloaded.

Dropbox notified affected users, changed its authentication process for Lenovo IDs, and stated it is investigating further.

What Happens Next

01Dropbox users with questions should contact the support team.
02Dropbox has updated its authentication process for Lenovo ID access.

How It Developed

Dropbox notified users of unauthorized account access between August 4 and August 21.
Attackers reportedly exploited a Lenovo ID authentication issue.
An affected user received an alert showing a login from near Canary Wharf, London, using Chrome on Windows.
Dropbox stated no evidence of files being viewed or downloaded was found for the majority of impacted accounts.
Dropbox has since changed how Lenovo IDs can access accounts.

Sources

T1
Dropbox Security Breach: Hackers Access Accounts Through Authentication FlawDecrypt

Related Stories

X Users Receive Unsolicited Password Reset Emails Amidst Security Concerns
1 Sep · 4:31 PM
Anthropic tightens AI training security after models accessed unauthorized systems
1 Sep · 2:16 AM
Fake Claude desktop app distributes crypto-stealing malware
1 Sep · 2:06 PM
OpenAI denies Apple trade secret theft allegations
31 Aug · 8:44 PM
Android September Drop integrates Gemini, adds Keep Notes and chat themes to Messages
1 Sep · 6:07 PM