Hackers gained access to Dropbox user files: company reveals scale of hack

Dropbox logo / unsplash
Фото: Dropbox logo / unsplash

Hackers gained unauthorized access to approximately 5000 accounts of the Dropbox cloud service. In some cases, the attackers were able to view or download users' files.

According to Dropbox, the unauthorized access occurred between August 4 and August 21. Files were viewed or downloaded in less than a third of the compromised accounts. After discovering the issue, the company secured the accounts and began notifying affected users and data protection regulators.

The attack was linked to the Lenovo ID login system. As explained by Dropbox, a flaw in Lenovo's email verification process allowed a third party to create a Lenovo ID with another user's email address. This profile could then be used to log into the Dropbox account associated with that address.

Accounts that did not have Dropbox two-factor authentication enabled were affected. In some cases, the attackers did not need to know the Dropbox password or gain access to the victim's mailbox.

After the incident, Dropbox ended all active sessions authorized via Lenovo ID and removed existing links between Lenovo profiles and Dropbox accounts. The company also changed the login mechanism: now, to access via Lenovo, the user must additionally enter a Dropbox password. 

Lenovo, for its part, stated a problem in the old Lenovo ID integration with Dropbox, which could be used for improper authorization of certain cloud service accounts. The company noted that Lenovo's own customers were not affected by the incident, and the investigation is ongoing. 

News of the breach also affected Dropbox's stock quotations. According to Bloomberg, the company's shares fell by 6.6% at one point after the closing of the main trading session on Tuesday.

Based on materials from: Bloomberg, 9to5Mac

analytics