Thousands of Dropbox Accounts Accessed Without Passwords Through Lenovo ID Flaw


dropbox breach
Image credit: Dropbox

Dropbox accounts accessed through a Lenovo ID flaw allowed attackers to enter some users’ accounts without knowing their Dropbox passwords.

Dropbox says attackers exploited a weakness in Lenovo’s email verification process. The flaw allowed someone to create a Lenovo ID using another person’s email address and then use that identity to access the Dropbox account tied to the same address.

Affected Dropbox users did not need to have an existing Lenovo account for the attack to work.

Attackers accessed Dropbox accounts in August

Dropbox determined that unauthorized access took place between August 4 and August 21.

Some affected users had already noticed suspicious login activity. Others saw an unexpected “Continue with SSO” option connected to a Lenovo ID they had never created.

The issue stemmed from Lenovo Identity Provider Services and how Lenovo verified ownership of email addresses.

An attacker could create a Lenovo ID with a victim’s email address, while Lenovo incorrectly confirmed that the attacker controlled that address. Dropbox trusted Lenovo’s authentication and allowed the fraudulent Lenovo ID to access the Dropbox account associated with the email.

The attacker did not need the victim’s Dropbox password.

Legacy Lenovo and Dropbox integration enabled the attack

Lenovo explained that a legacy integration between Lenovo ID and Dropbox made the attack possible.

Because Dropbox treated Lenovo’s identity verification as trusted authentication, gaining control of a fraudulent Lenovo ID could provide access to the matching Dropbox account.

Dropbox and Lenovo worked together to mitigate the problem after discovering it. The companies continue to investigate the incident.

Around 5,000 Dropbox accounts were reportedly accessed

Reuters reports that attackers accessed approximately 5,000 Dropbox accounts during the incident.

The attacker reportedly viewed and downloaded files from some compromised accounts.

Lenovo says the incident did not affect its own customers.

Dropbox now requires passwords for Lenovo ID logins

Dropbox has expired all existing sessions that authenticated through Lenovo IDs.

The company also changed how Lenovo ID authentication works. Users who attempt to sign in through Lenovo ID must now enter their Dropbox account password as an additional verification step.

This change prevents a Lenovo ID alone from providing access to a Dropbox account associated with the same email address.

In other security news, Microsoft recently uncovered a fake software download malware campaign, while Microsoft Defender is currently falsely flagging Google Search URLs. Microsoft also plans to turn on Memory Integrity automatically on Windows 11 in the future.

Via BleepingComputer

More about the topics: dropbox, security

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages