Dropbox Warns Users of Account Intrusions Linked to Lenovo ID Verification Flaw
Dropbox has issued an alert to a subset of its users after an unauthorized actor gained access to accounts by exploiting a vulnerability in Lenovo's email verification process to create fraudulent Lenovo IDs.
The weakness in Lenovo's system allowed attackers to validate any email address without proper checks, enabling them to register Lenovo credentials that appeared legitimate. Those counterfeit IDs were then used to authenticate through Dropbox's single‑sign‑on integration, giving the intruder the ability to reset passwords and take control of the affected Dropbox accounts.
While Dropbox has not disclosed the exact number of compromised accounts, it advises all users to change passwords immediately and enable two‑factor authentication. The company says there is no indication that large‑scale data was exfiltrated, but it continues to monitor for suspicious activity and is cooperating with Lenovo to investigate the breach.
Dropbox has faced security incidents in the past, and reliance on third‑party identity providers is a common practice that can introduce additional risk. Lenovo confirmed that it has patched the email verification flaw after being notified by security researchers, and it is reviewing its onboarding procedures to prevent similar exploitation.
Experts recommend that users review recent login activity, employ unique, strong passwords, and consider using a password manager. The incident serves as a reminder that even well‑established services can be vulnerable when linked to external authentication systems, underscoring the need for rigorous verification methods across the tech ecosystem.
Comments (0)
Be the first to comment.
Join the discussion