Hackers Accessed 5,000 Dropbox Accounts Through Lenovo ID Flaw

Hackers Accessed 5,000 Dropbox Accounts Through Lenovo ID Flaw

Listen to this article

0:00

Press play to start listening

A flaw in Lenovo ID’s email verification process allowed an unauthorized party to access about 5,000 Dropbox accounts between 4 and 21 August. Dropbox said files were viewed or downloaded in fewer than one-third of the affected accounts.

Dropbox began notifying affected users on Monday, 31 August, and one recipient shared screenshots of the notice on X. The affected accounts were accessed through Lenovo ID and did not have Dropbox two-factor authentication enabled. Victims did not necessarily have an existing Lenovo ID because the attacker could register one using their email address.

Dropbox notification shared by Yoni Levy on X (Source: Yoni Levy/X)

Attack Details

The incident involved a legacy integration that allowed users to access Dropbox through Lenovo ID, Lenovo’s identity and login system.

According to Dropbox, an issue with Lenovo’s email verification process allowed an unauthorized person to register a Lenovo ID using someone else’s email address without proving they controlled the inbox.

The attacker could then use that newly created Lenovo ID to sign into the Dropbox account associated with the same email address. The linked login method therefore allowed access without requiring the victim’s Dropbox password.

Dropbox Changes Lenovo Login Flow

Dropbox responded by terminating sessions authenticated through Lenovo IDs and removing the links between Lenovo IDs and Dropbox accounts. The company also changed the login process so users must enter their Dropbox password before accessing an account through the Lenovo integration.

Lenovo worked with Dropbox to address the issue staging that its own customers were not affected and that its investigation remained ongoing. Dropbox also reported the incident to data protection regulators.

This incident is another example of how old or unused connections between services can create security problems if they are not properly secured or removed. In June, attackers compromised competitive-intelligence platform Klue through a long-unused credential tied to a test integration and used stolen OAuth tokens to access connected Salesforce and Gong environments.

Commenting on the Dropbox incident, Dan Moore, senior director of CIAM strategy and identity standards at FusionAuth, told Hackread.com:

“This Dropbox account takeover highlights a dangerous emerging trend where attackers create fake accounts at a trusted federated identity source. The application then accepted tokens from those controlled accounts and linked them to application user profiles without requiring any verification from the real owner. The June Meta AI chatbot exploit worked in a similar way by allowing attackers to add recovery emails to target Instagram accounts and reset passwords. Modifying an account to add an additional login method should require the user to prove they own it.”

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts