In an email to affected customers, Dropbox said attackers exploited an integration that allowed users to access their accounts via Lenovo IDs. The company blamed "an issue with Lenovo's email verification process" without specifying why the integration did not require a Dropbox password for access.
Dropbox told Bloomberg that attackers accessed files belonging to fewer than one-third of the affected users. Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. "Sometimes, it pays to be a nerd," Lopp remarked.
Dropbox confirmed to Reuters that none of the compromised accounts had two-factor authentication (2FA) enabled. After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo. The company advised affected users to change their Dropbox and personal email passwords and enable 2FA.
Lenovo told Reuters that its customers were unaffected and that its investigation was continuing. The Register has sought additional comment from both companies.