Dropbox warned users that an unauthorized party accessed some accounts by abusing a flaw in Lenovo’s email verification process to create fraudulent Lenovo IDs tied to victims’ email addresses. The attacker then used Lenovo ID-based authentication to log into Dropbox without needing the account password, prompting Dropbox to expire affected sessions and require passwords for Lenovo ID sign-ins. #Dropbox #Lenovo
Keypoints
- Dropbox said some accounts were accessed through Lenovo Identity Provider Services.
- An email verification flaw let an attacker register a Lenovo ID using someone else’s email address.
- The fraudulent Lenovo ID was then used to sign in to the linked Dropbox account without a password.
- Dropbox and Lenovo said the issue involved a legacy integration and worked to mitigate it.
- Dropbox expired Lenovo-authenticated sessions and added a password requirement for Lenovo ID logins.