Legacy Lenovo login tied to Dropbox account hacks
Dropbox says attackers abused a legacy Lenovo login integration to access 5,000 accounts.
Dropbox has alerted roughly 5,000 users that attackers gained access to their cloud storage accounts by abusing an outdated Lenovo login integration. The breach, which went on for more than two weeks, underscores how legacy authentication paths can become quiet backdoors when they are left connected.
Lenovo ID abuse
In an email sent to affected customers, the cloud storage company said attackers exploited an integration that allowed users to access Dropbox using Lenovo IDs. Dropbox attributed the incident to "an issue with Lenovo's email verification process," which let attackers register Lenovo IDs using Dropbox users' email addresses and then access the corresponding storage accounts.
The company did not explain why the integration was allowed to grant access without requiring the user to enter a Dropbox password.
Two-week window
The compromise lasted from August 4 to 21. Dropbox told Bloomberg that attackers accessed files belonging to fewer than a third of the affected users. Jameson Lopp, co-founder of Bitcoin security company Casa, said attackers attempted to access just one of his files, "IMPORTANT.rtf," which had been encrypted locally before it was uploaded to Dropbox. Sometimes, it pays to be a nerd.
Dropbox confirmed the scale of the attack to Reuters and said none of the affected accounts had two-factor authentication (2FA) enabled.
Response and next steps
After discovering the breach, Dropbox said it "promptly expired all sessions logged in through Lenovo IDs" and "severed any link" between the affected accounts and Lenovo.
"promptly expired all sessions logged in through Lenovo IDs"
— Dropbox statement
In its email, the company advised affected users to change their Dropbox and personal email passwords and enable 2FA.
Lenovo's stance
Lenovo told Reuters that its customers were unaffected and that its investigation was continuing. The Register asked Dropbox and Lenovo for more information.
What this means for users
This incident highlights the risks of legacy integrations and the importance of enabling 2FA. Even with the integration severed, affected users should take immediate steps to secure their accounts. The lack of 2FA on all compromised accounts suggests that additional security layers could have prevented or limited the attack.
Sources
- The Register Original source
Continue Reading
MSP Ransomware Defense Needs More Than Backups
Acronis data shows 143 MSP victims in 2025. A six-point checklist helps providers verify real recovery capability.
SonicWall SMA 1000 Zero-Days Exploited in Chained Attacks
SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.
BGP hijack pushes malware via a 256-IP range
Attackers exploited routing and TLS flaws to abuse a hijacked /24 block in a 22-hour window.