Cryptopolitan
2026-09-02 16:00:33

Dropbox says 5,000 accounts breached in data hack via Lenovo ID integration

Cloud storage service Dropbox informed about 5,000 users this week that their accounts were accessed by hackers between August 4 and August 21, 2026, due to a dormant Lenovo ID sign-in integration that allowed the attackers direct access without the use of a password. The users at risk were Dropbox users who stored files in the cloud storage app and never initiated multi-factor authentication. Dropbox login accessed without a password The loophole that granted the attackers access was the integration connection between Lenovo ID and Dropbox, and not any of the products particularly. According to TheNextWeb, anyone could register a Lenovo ID against an email address that was not theirs, because Lenovo’s setup never confirmed the address belonged to them. Dropbox, however, saw the Lenovo token as a proof of identity and then allowed access to the matching account. The security writer The CyberSec Guru, cited by 9to5Mac, described the timeline of events. Bad actors and hackers collect public email addresses, after which they enroll a Lenovo ID under a victim’s address. The hackers then used the “Continue with Lenovo” option on Dropbox, handing them access to a live session that does not require a password prompt and subsequently direct access to the Dropbox account. One user who reclaimed a previously accessed rogue account found it carried the display name “John Madden,” which 9to5Mac claims is a sign of bulk registrations. What was lost in the attack? Files were viewed or downloaded on less than a third of the approximately 5,000 accounts opened over the period of this attack. This means there were about 1,500 accounts where material was actually taken, according to 9to5Mac’s update, and around 3,500 where there were no traces of files being touched. It remains unclear if the intruders were after specific documents or simply swept through accounts automatically. The hackers were said to have viewed and downloaded material on a smaller share of accounts, and spokesperson Tim Rathschmidt stated that none of the breached accounts used multi-factor authentication. Rathschmidt also added that Dropbox does not expect this incident to be a hit on its business. Dropbox switches off Lenovo ID integration Upon finding out about the issue, Dropbox killed every session that had been authenticated through a Lenovo ID, switched off the integration, and now demands a native Dropbox password before any account can be accessed. Lenovo traced the hack to a “legacy integration” that it claimed could be used to “improperly authenticate certain Dropbox accounts.” The company said its own users remained completely unaffected, and confirmed that its investigation was still open. The breach surfaced via a later investigation and was not picked up by the monitoring systems of both companies. Multi-factor authentication would have blocked the attack, because the loophole took advantage of the need for no password using the Lenovo ID integration, granting access if there was no second check for certainty. The smartest crypto minds already read our newsletter. Want in? Join them .

La maggior parte ha letto le notizie

Notizie correlate

Ricevi la newsletter di Crypto
Leggi la dichiarazione di non responsabilità : Tutti i contenuti forniti nel nostro sito Web, i siti con collegamento ipertestuale, le applicazioni associate, i forum, i blog, gli account dei social media e altre piattaforme ("Sito") sono solo per le vostre informazioni generali, procurati da fonti di terze parti. Non rilasciamo alcuna garanzia di alcun tipo in relazione al nostro contenuto, incluso ma non limitato a accuratezza e aggiornamento. Nessuna parte del contenuto che forniamo costituisce consulenza finanziaria, consulenza legale o qualsiasi altra forma di consulenza intesa per la vostra specifica dipendenza per qualsiasi scopo. Qualsiasi uso o affidamento sui nostri contenuti è esclusivamente a proprio rischio e discrezione. Devi condurre la tua ricerca, rivedere, analizzare e verificare i nostri contenuti prima di fare affidamento su di essi. Il trading è un'attività altamente rischiosa che può portare a perdite importanti, pertanto si prega di consultare il proprio consulente finanziario prima di prendere qualsiasi decisione. Nessun contenuto sul nostro sito è pensato per essere una sollecitazione o un'offerta