Dropbox has disclosed that an attacker exploited a vulnerability in Lenovo's email verification system to register Lenovo IDs using victims' email addresses, then used those IDs to log into Dropbox accounts linked to the same email addresses — bypassing the need for passwords entirely.
The cloud-storage provider uses Lenovo Identity Provider Services as part of its authentication infrastructure, allowing users to log in using verified Lenovo IDs. In a notification sent to impacted users, Dropbox explained that "an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address."
Some affected users reported receiving suspicious login notifications approximately two weeks before the breach was disclosed. One user on Hacker News noted that the Dropbox login page had started offering "Continue with SSO" for their email even though they had never created a Lenovo ID.
The breach affected accounts accessed between August 4 and August 21, with Reuters reporting that roughly 5,000 accounts were compromised. The attacker viewed and downloaded content from some users.
In a statement to BleepingComputer, Lenovo said the issue stemmed from a legacy integration between Lenovo ID and Dropbox that "could be leveraged to improperly authenticate certain Dropbox accounts." A Lenovo spokesperson added, "Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk."
Lenovo stated that its own customers were not affected by the vulnerability. Dropbox has responded by expiring all sessions authenticated through Lenovo IDs and implementing a new requirement that users must enter their Dropbox account password even when using Lenovo ID authentication.