A vulnerability in Lenovo’s email verification process exposed around 5,000 Dropbox user accounts, according to Dropbox’s notification to affected individuals.
Dropbox uses Lenovo as an identity provider, allowing users to sign in with verified Lenovo IDs. The flaw allowed an unauthorized party to create a Lenovo ID with someone else’s email address and use it to access the Dropbox account linked to that address.
The attack took place between August 4 and 21. Most of the accessed accounts did not have 2FA enabled. Dropbox said there was evidence that stored documents were viewed or downloaded in around a third of the affected accounts.
Dropbox said it has addressed the vulnerability, expired all sessions logged in through Lenovo IDs, and ended the links between Lenovo and Dropbox accounts. Logging in through a Lenovo ID now requires the Dropbox password.
Dropbox also urged affected users to change their passwords, enable two-step verification, and change the passwords for their email accounts.
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said the incident showed the risks of unreviewed third-party authentication pathways and accounts without MFA. He said organisations and individuals should periodically review which third-party services can authenticate to their accounts.
Comments
0No comments yet. Be the first to comment.