How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
Hackers exploited a legacy login integration between Lenovo's identity system and Dropbox, gaining access to approximately 5,000 Dropbox accounts. The vulnerability stemmed from a loophole allowing attackers to register Lenovo accounts using compromised email addresses, bypassing Dropbox's usual security measures. Dropbox has since terminated sessions using Lenovo IDs and requires a password for login, while users are advised to reset passwords and enable two-factor authentication.
Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, following a security breach linked to a legacy login integration between Lenovo's identity system and Dropbox. The issue arose because attackers were able to register Lenovo accounts using compromised email addresses, bypassing Dropbox’s standard security protocols. Dropbox sent a warning to affected users about an issue with Lenovo’s email verification process, which allowed attackers to sign up for a Lenovo account using someone else’s email address without verifying ownership of the inbox.
Lenovo stated that its own customers and systems were unaffected, and that it collaborated with Dropbox to quickly address the risk. Dropbox has since terminated all sessions authenticated through a Lenovo ID and now requires a user’s actual Dropbox password to be entered, even when logging in via Lenovo ID, effectively closing the loophole.
Affected users have been instructed to reset their Dropbox and email passwords, and to enable two-factor authentication (2FA) to bolster their account security. This incident highlights the importance of robust identity management and the potential risks associated with relying on legacy integrations between different systems.
Despite the relatively small number of accounts accessed, the incident underscores the need for vigilance and proactive security measures. It’s a reminder that vulnerabilities can arise from seemingly simple oversights in identity management and that even a small number of compromised accounts can represent a significant risk.