CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5869

As cited

Copy frozen at (site build).

breaches incidents

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

Attackers compromised approximately 5,000 Dropbox accounts between August 4 and 21 by exploiting a legacy Lenovo login integration and a flaw in Lenovo's email verification process that allowed account registration using Dropbox users' email addresses. None of the affected accounts had multifactor authentication (MFA) enabled. Dropbox has disabled the Lenovo integration, expired affected sessions, and recommended users change passwords and enable MFA.

Why it matters: Dropbox users who relied on Lenovo ID login should immediately check their accounts for unauthorized access and enable MFA, as attackers accessed files in fewer than one-third of compromised accounts during the attack window.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary