Dropbox confirms unauthorized access to thousands of accounts during August security incident linked to a third-party Lenovo ID vulnerability
A routine third-party link has turned into a major security headache for thousands of cloud storage users.
Unauthorized access occurred over a nearly three-week window, impacting approximately 5,000 Dropbox user accounts.
Some users received an email from the company on Monday notifying them that their accounts have been accessed without authorization between August 4 and August 21.
As reported by Bloomberg News, the company said hackers accessed files in fewer than a third of the compromised accounts.
The cloud-based file hosting and storage service informed that it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, prompting the company to terminate all sessions authenticated through a Lenovo ID.
In response, the cloud-based service has removed any links between Lenovo IDs and Dropbox accounts and changed its systems so that users must enter their Dropbox password before accessing an account through Lenovo.
Dropbox said it had reported the incident to data protection regulators.
Lenovo identified a "legacy integration" between Lenovo ID and Dropbox that "could be used to improperly authenticate certain Dropbox accounts".
The company said its own customers were not affected and that an investigation was ongoing.
Attackers exploited a legacy third-party integration and email verification flaw related to Lenovo ID.
Malicious actors registered fraudulent Lenovo IDs using victims' email addresses to bypass standard password checks and gain entry.
Dropbox confirmed that all compromised accounts lacked multi-factor authentication (MFA).
While around 5,000 accounts were breached, files were viewed or downloaded in fewer than one-third of those instances.
Dropbox has terminated all active sessions linked to Lenovo IDs, severed the integration mechanism, and updated its systems to mandate native password verification.
Both companies stated that investigations are ongoing and affected users and regulators have been notified.
As per Dropbox, the company shares fell around 2.4% in extended trading on Tuesday.