Hackers Accessed Thousands Of Dropbox Accounts Through Lenovo ID Flaw
Source: HackRead A flaw in Lenovo ID’s email verification process allowed an unauthorized party to access about 5,000 Dropbox accounts between Aug. 4 and Aug.
21. Dropbox said files were viewed or downloaded in fewer than one-third of the affected accounts. Dropbox began notifying affected users on Aug.
31. The affected accounts were accessed through Lenovo ID and did not have Dropbox two-factor authentication enabled. Victims did not necessarily have an existing Lenovo ID because the attacker could register one using their email address. The incident involved a legacy integration that allowed users to access Dropbox through Lenovo ID, Lenovo’s identity and login system.
Full Story
Share this signal