A security flaw in Lenovo's email verification system allowed hackers to gain access to approximately 5,000 Dropbox accounts. The breach occurred between August 4 and 21, and it was possible because attackers could create Lenovo IDs using victims' email addresses. Most of the affected accounts did not have two-factor authentication (2FA) enabled, which is an extra layer of security that requires users to verify their identity through a second method, such as a code sent to their phone.
Dropbox informed the affected users about the issue and confirmed that the vulnerability has been fixed. To protect user privacy, Dropbox took steps such as ending all active sessions that were logged in through Lenovo IDs and disconnecting all links between Lenovo and Dropbox accounts. Now, users must enter their Dropbox password when logging in through a Lenovo ID, which means no one can access a Dropbox account via a Lenovo ID without first providing the Dropbox password.
Dropbox has advised users to change their passwords, enable two-factor authentication, and update their email account passwords as well. According to Muhammad Yahya Patel, a cybersecurity advisor for EMEA at Huntress, the absence of multi-factor authentication in the compromised accounts was a major security risk. He highlighted the importance of regularly checking third-party services that have access to account credentials to ensure they are secure.
The incident underscores the risks of relying on a single method of authentication for online accounts. Experts recommend that users always enable two-factor authentication where possible and be cautious about which third-party services have access to their personal information. By taking these steps, users can reduce the chances of their accounts being compromised in similar attacks.
Dropbox Accounts Compromised via Lenovo ID Verification Flaw
AI-rewritten from original reportingHow it works
lenovodropboxsecurityvulnerability2facybersecurity



