Dropbox accounts breached through Lenovo email verification flaw

Dropbox accounts breached through Lenovo email verification flaw
Dropbox warned users that an unauthorized party accessed some accounts by abusing a flaw in Lenovo’s email verification process to create fraudulent Lenovo IDs tied to victims’ email addresses. The attacker then used Lenovo ID-based authentication to log into Dropbox without needing the account password, prompting Dropbox to expire affected sessions and require passwords for Lenovo ID sign-ins. #Dropbox #Lenovo

Keypoints

  • Dropbox said some accounts were accessed through Lenovo Identity Provider Services.
  • An email verification flaw let an attacker register a Lenovo ID using someone else’s email address.
  • The fraudulent Lenovo ID was then used to sign in to the linked Dropbox account without a password.
  • Dropbox and Lenovo said the issue involved a legacy integration and worked to mitigate it.
  • Dropbox expired Lenovo-authenticated sessions and added a password requirement for Lenovo ID logins.

Read More: https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/