started · updated
Dropbox accounts compromised via Lenovo ID vulnerability
Approximately 5,000 Dropbox user accounts were compromised between August 4 and August 21 due to a vulnerability in Lenovo’s email verification process. The breach exploited a legacy integration where Dropbox used Lenovo ID as an identity provider.
Attackers were able to register a Lenovo ID using a victim's email address without verifying ownership of that email inbox. Because of the existing integration, these unauthorized Lenovo IDs allowed hackers to log directly into associated Dropbox accounts without being prompted for a Dropbox password. This vulnerability was particularly effective against accounts that did not have two-factor authentication (2FA) enabled.
Dropbox reported that in roughly one-third of the affected accounts, there is evidence that stored documents were viewed or downloaded. In response, Dropbox has terminated all sessions authenticated via Lenovo IDs and has updated the login process to require a Dropbox password even when using a Lenovo ID. The company has urged affected users to change their passwords, enable two-step verification, and update their email account credentials.