As cited
Copy frozen at (site build).
breaches incidents
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Attackers compromised approximately 5,000 Dropbox accounts between August 4 and 21 by exploiting a legacy Lenovo login integration and a flaw in Lenovo's email verification process that allowed account registration using Dropbox users' email addresses. None of the affected accounts had multifactor authentication (MFA) enabled. Dropbox has disabled the Lenovo integration, expired affected sessions, and recommended users change passwords and enable MFA.
Why it matters: Dropbox users who relied on Lenovo ID login should immediately check their accounts for unauthorized access and enable MFA, as attackers accessed files in fewer than one-third of compromised accounts during the attack window.
- Source published
- First seen by Cybersecurity Tracker