Thousands of Dropbox accounts compromised via Lenovo ID flaw

 

Thousands of Dropbox accounts compromised via Lenovo ID flaw

Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process.

The attackers were able to create fake Lenovo IDs using victims’ email addresses. They then used the Lenovo IDs to sign in to Dropbox accounts linked to the same email addresses without knowing the users’ Dropbox passwords.

The issue was linked to a legacy integration between Lenovo ID and Dropbox. Dropbox uses Lenovo Identity Provider Services as part of its authentication system, allowing users to sign in with verified Lenovo IDs. However, the system trusted Lenovo’s confirmation that the person controlled an email address without requiring an additional check through the existing Dropbox login.

This meant that even users who never had a Lenovo account could be affected. According to Dropbox notifications sent to impacted users, the flaw in Lenovo’s email verification process allowed attackers to register Lenovo IDs with other people’s email addresses and use them to access the corresponding Dropbox accounts.

Some affected users reported receiving suspicious Dropbox login notifications about two weeks ago.

Dropbox’s spokesperson Tim Rathschmidt told Bloomberg that the intruders compromised around 5,000 Dropbox accounts and accessed files in nearly third of them.

Lenovo said the issue involved its legacy integration with Dropbox and could be used to improperly authenticate certain Dropbox accounts. The company said its investigation found that Lenovo customers were not affected.

Back to the list