Some Dropbox users had their accounts accessed by an unauthorized attacker after a flaw in Lenovo’s email verification process was used to create fraudulent Lenovo IDs.
The issue affected users even if they never had a Lenovo account because Dropbox uses Lenovo Identity Provider Services as part of its authentication system.
According to notifications sent to affected users, the problem allowed an attacker to register a Lenovo ID using someone else’s email address. The attacker could then use that fraudulent Lenovo ID to access the Dropbox account associated with the same email address without knowing the user’s Dropbox password.
Dropbox’s identity-linking system trusted Lenovo’s confirmation that the attacker controlled the email address without requiring additional verification through the existing Dropbox login method. This allowed the fraudulent Lenovo account to be used as a way into the victim’s Dropbox account.
Some users said they received suspicious login notifications and responded by changing their passwords and enabling two-factor authentication. One user also noticed that Dropbox had suddenly started offering a “Continue with SSO” option for their email address despite never creating a Lenovo ID.
Dropbox determined that attackers accessed affected accounts between August 4 and August 21. Lenovo said the problem was connected to a legacy integration between Lenovo ID and Dropbox that could be abused to improperly authenticate certain Dropbox accounts.
Dropbox responded by expiring all sessions that had been authenticated through Lenovo IDs. The company also added a new requirement for users to enter their Dropbox account password when attempting to sign in through Lenovo ID authentication.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
According to Reuters, around 5,000 Dropbox accounts were accessed during the incident, with attackers viewing and downloading content from some accounts. The investigation into the incident is still ongoing, while Lenovo said its customers were not affected by the issue.





