Hackers Access About 5,000 Dropbox Accounts Using Lenovo Login Flaw
Hackers exploited a broken Lenovo ID login path to access about 5,000 Dropbox accounts, reaching files in less than a third of cases. Because users could sign in via a linked Lenovo ID without re-entering a Dropbox password, no Dropbox password was required. Dropbox later expired Lenovo-authenticated sessions, cut the link, required Dropbox passwords for Lenovo sign-ins, and notified regulators and affected users.
Coverage (10)
- Dropbox hit by security incident linked to Lenovo verification vulnerability (teiss.co.uk)
- Thousands of Dropbox accounts breached via Lenovo flaw (computing.co.uk)
- Hacker Breaches Dropbox Accounts Via Lenovo ID System (me.pcmag.com)
- Legacy Lenovo login opens 5,000 Dropbox accounts to attackers (theregister.com)
- Hacker Breaches Dropbox Accounts Via Lenovo ID System (pcmag.com)
- Dropbox Account Hack Compromises 5,000 Accounts (stratnewsglobal.com)
- Dropbox hack exposes 5,000 accounts after Lenovo ID security flaw (thenews.com.pk)
- Dropbox Says Roughly 5,000 Accounts Hit in August Breach Tied to Lenovo ID Flaw (finance.biggo.com)
- Dropbox user accounts breached by hackers who accessed data (straitstimes.com)
- Hackers Broke Into 5,000 Dropbox Accounts Through a Lenovo Login Flaw (startupfortune.com)