Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
- Hackers exploited Lenovo’s flawed email verification to hijack ~5,000 Dropbox accounts
- Attackers created Lenovo IDs with victims’ emails, bypassing login; 2FA absence worsened impact
- Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup
Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What does a Lenovo flaw have to do with people’s Dropbox accounts, you might ask? Here is what happened:
Earlier this week, Dropbox started notifying affected individuals about the incident. In the data breach notification email, the company explains:
“Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE