Hackers were able to gain access to approximately 5,000 Dropbox accounts last month after exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. Clouds are seen in front of the Dropbox logo in this illustration taken February 27, 2022. REUTERS/Dado Ruvic/IllustrationAccording to a notification sent to the affected users, "an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address" - in some cases, users didn't even have Lenovo accounts. The hackers then used the fraudulent Lenovo ID to access the Dropbox account associated with the same email address without needing the login password, BleepingComputer notes. The accounts were accessed August 4th through the 21st. so dropbox got hacked (never had a Lenovo account, haven't been to UK) pic.twitter.com/UoYRaJFuEC — yoni | parser.eth (@yonilevy) August 31, 2026Users reported receiving strange notifications "about two weeks ago," urging them to change their password and activate two-factor authentication (2FA). "One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID," according to one person. Lenovo told BleepingComputer that the issue was connected to a legacy integration between Lenovo ID and Dropbox, which was used "to improperly authenticate certain Dropbox accounts.""Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk," the spokesperson continued. Dropbox forced all sessions authenticated via Lenovo ID to expire, and added a new login requirement forcing users to use their Dropbox account password instead.
Thousands Of Dropbox Accounts Breached In 'Verification' Hack
Full Article
Original Source
Read the full article at Zerohedge →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.