Dropbox says hackers compromised around 5,000 user accounts last month and were able to view and download files stored on the cloud-storage platform.
The company said some affected users were notified by email on Monday after unauthorized access was detected between August 4 and August 21. Dropbox confirmed the incident after Bloomberg News first reported the hack.
According to Dropbox, attackers accessed files in fewer than one-third of the compromised accounts. The company has not indicated that all 5,000 affected accounts had their stored content accessed.
The incident was linked to accounts connected to a Lenovo ID that did not have two-factor authentication enabled. Dropbox said it has terminated all sessions authenticated through a Lenovo ID as part of its response to the attack.
Dropbox has also removed the connection between Lenovo IDs and Dropbox accounts and changed its authentication process. Users will now have to enter their Dropbox password before they can access an account through Lenovo.
Lenovo said it discovered a legacy integration between Lenovo ID and Dropbox that could be used to improperly authenticate certain Dropbox accounts. The company said its own customers were not affected and that its investigation into the issue is still underway.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Dropbox has reported the incident to data protection regulators as it continues investigating what happened and assessing the impact on affected users.
Dropbox Says Hackers Compromised About 5,000 Accounts





