Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Cloud storage biz severs old integration and urges victims to reset credentials
Dropbox has warned around 5,000 users that attackers compromised their accounts by abusing a legacy Lenovo login integration.
In an email sent to affected customers, the cloud storage biz said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs.
Dropbox blamed "an issue with Lenovo's email verification process," which allowed attackers to register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts.
It did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password.
The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users.
Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf,"...
Copyright of this story solely belongs to theregister.com. To see the full text click HERE