Hackers exploit Lenovo ID flaw to breach thousands of Dropbox accounts
Hackers accessed about 5,000 Dropbox accounts in August by abusing Lenovo ID credentials, viewing or downloading files on a portion of them.
A breach affecting roughly 5,000 Dropbox accounts occurred between early and late August, with hackers leveraging counterfeit Lenovo ID usernames and passwords to infiltrate the cloud storage service. The intruders were able to view or download files from fewer than a third of the compromised accounts, while the rest showed no sign of data being accessed. Dropbox learned of the incident, promptly secured the affected accounts, and informed both regulators and the users involved.
Notification emails sent on August 31 explained that some accounts lacked multi-factor authentication, which facilitated the attack. Lenovo acknowledged a legacy integration issue that allowed the misuse of its ID system and said it was working with Dropbox to mitigate the risk, stating its own customers were not impacted. The company does not anticipate a material effect on its business from the breach, and its shares fell up to 6.6% in after-hours trading on September 1.
Why it matters
The incident shows how weak authentication and third-party integrations can expose millions of cloud users to data theft.
In this story
