Dropbox accounts compromised via Lenovo email verification flaw, 5,000 affected

Cloud storage provider says unauthorized party exploited legacy integration to access accounts without passwords

edit
By LineZotpaper
Published
Read Time2 min
Dropbox is warning some users that an unauthorized party accessed their accounts between August 4 and 21 by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs, with approximately 5,000 accounts affected according to Reuters.

Dropbox has disclosed that an attacker exploited a vulnerability in Lenovo's email verification system to register Lenovo IDs using victims' email addresses, then used those IDs to log into Dropbox accounts linked to the same email addresses — bypassing the need for passwords entirely.

The cloud-storage provider uses Lenovo Identity Provider Services as part of its authentication infrastructure, allowing users to log in using verified Lenovo IDs. In a notification sent to impacted users, Dropbox explained that "an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address."

Some affected users reported receiving suspicious login notifications approximately two weeks before the breach was disclosed. One user on Hacker News noted that the Dropbox login page had started offering "Continue with SSO" for their email even though they had never created a Lenovo ID.

The breach affected accounts accessed between August 4 and August 21, with Reuters reporting that roughly 5,000 accounts were compromised. The attacker viewed and downloaded content from some users.

In a statement to BleepingComputer, Lenovo said the issue stemmed from a legacy integration between Lenovo ID and Dropbox that "could be leveraged to improperly authenticate certain Dropbox accounts." A Lenovo spokesperson added, "Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk."

Lenovo stated that its own customers were not affected by the vulnerability. Dropbox has responded by expiring all sessions authenticated through Lenovo IDs and implementing a new requirement that users must enter their Dropbox account password even when using Lenovo ID authentication.

§

Analysis

Why This Matters

  • The breach demonstrates how reliance on third-party identity providers can create unexpected attack surfaces — even for users who never signed up for the provider's service.
  • Approximately 5,000 accounts were accessed, and data was exfiltrated, exposing users to potential privacy risks and credential reuse attacks.
  • The incident highlights the importance of verifying authentication flows end-to-end, especially when linking identity systems across companies.

Background

Single sign-on (SSO) services allow users to access multiple platforms with one set of credentials, improving convenience but also creating a single point of failure. In this case, Dropbox's authentication infrastructure trusted Lenovo's identity assertions without requiring additional verification from the user's existing Dropbox login. The flaw in Lenovo's email verification process allowed an attacker to create a Lenovo ID under someone else's email address, effectively stealing that identity for authentication purposes.

Key Perspectives

Dropbox: The company has notified affected users, expired sessions, and added password verification for Lenovo ID logins. It has not disclosed whether it will offer credit monitoring or other remediation. Lenovo: Acknowledged the issue as a legacy integration vulnerability, says Lenovo customers were not affected, and is cooperating with Dropbox on the investigation. Affected users: Some report having no Lenovo account yet still being compromised. They face potential data theft and reliance on Dropbox's response measures.

What to Watch

  • Further details from Dropbox and Lenovo's ongoing investigation into how the attacker exploited the flaw and whether additional accounts were accessed.
  • Whether affected users report instances of identity theft or further account compromises.
  • Possible regulatory scrutiny or class-action lawsuits given the number of accounts compromised and the sensitivity of stored data.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.