Dropbox Accounts Hacked: Thousands of Files Accessed

By Business DeskDropbox Accounts Hacked: Thousands of Files Accessed

Thousands of Dropbox accounts were breached due to a Lenovo ID flaw, allowing hackers to access and download files. Learn how it happened and what Dropbox is doing.

Dropbox user accounts experienced a security breach last month, resulting in unauthorized access to approximately 5,000 accounts. Files were subsequently downloaded from less than a third of these compromised accounts over a period spanning August 4 to August 21.

A critical vulnerability identified was the absence of multifactor authentication on the affected accounts. This allowed the exploitation of a ‘legacy integration’ issue connected with Lenovo ID’s email verification process.

Vulnerability Exploitation Revealed

Hackers leveraged a flaw that enabled them to register Lenovo IDs using the email addresses of existing Dropbox users. This method provided them with unauthorized entry into the associated Dropbox accounts, even if users had no prior Lenovo account setup.

Upon discovering the intrusion, Dropbox moved swiftly to secure all affected accounts. The company has since confirmed that it informed both relevant regulators and the directly impacted users about the incident.

Company Response and Impact Assessment

Lenovo acknowledged the ‘legacy integration’ issue, confirming its collaboration with Dropbox to mitigate any potential risks. Lenovo also assured that its own customer accounts remained unaffected by this specific breach.

Despite the security incident, Dropbox does not anticipate any significant material impact on its overall business operations. The company maintains its assessment regarding the breach’s broader consequences.

Home/business/Article