Dropbox reports that 5,000 accounts were compromised via a Lenovo login.
An individual registered a Lenovo ID using a stranger's email address and subsequently accessed that person's Dropbox account without needing their password. According to Dropbox, around 5,000 accounts were compromised between August 4 and 21.
The issue originated from an outdated integration between Lenovo ID and Dropbox that failed to properly verify email ownership. Simply registering an account with someone else's email was sufficient to gain access as that individual.
In less than a third of the compromised accounts, files were viewed or downloaded. This implies that approximately 3,500 accounts were accessed without anything being stolen, though it's unclear whether the attackers were seeking specific files or simply accessing accounts automatically.
Every affected account lacked multi-factor authentication, a significant detail emphasized by Dropbox, as it highlights a key preventative measure against such attacks. Lenovo pinpointed the integration problem on its end and stated that its own customers were not impacted. The vulnerability stemmed from the connection between the two systems rather than either service individually.
Afterward, Dropbox terminated all sessions authenticated through Lenovo ID, completely disabled the integration, and now mandates a native Dropbox password to access an account. Affected users received notifications via email on Monday.
Multi-factor authentication would have prevented this incident since the flaw effectively circumvented the password, leaving no additional layer of verification. This serves as a crucial but straightforward lesson in an otherwise atypical breach.
Both companies have reported the incident to data protection authorities, and investigations are ongoing. For users in Europe, this entails compliance with GDPR notification obligations, including the 72-hour reporting deadline that applies once an organization becomes aware of a qualifying breach.
In extended trading, shares fell by approximately 2.4%, a relatively moderate response to a breach affecting 5,000 accounts of a company with hundreds of millions of users.
What makes this incident noteworthy is the nature of the attack rather than its scale. It wasn't solely a vulnerability in Dropbox or Lenovo, but rather an outdated trust relationship between the two systems that hadn't been reassessed.
The 17-day timeframe is also significant. The access occurring between August 4 and 21 went undetected through monitoring on either side and was only revealed through subsequent investigation.
Single sign-on integrations can build up over time and are seldom removed. Each creates additional access points to an account that do not rely on the account's own password, often based on security assumptions that made sense when the integration was first established.
The term "legacy" plays a crucial role in both companies' statements. In reality, it often depicts a system that remains operational because deactivating it could disrupt something, despite a lack of interest in its maintenance.
For enterprise clients, this raises a practical concern. A company storing business documents in Dropbox and relying on SSO through a hardware vendor's identity system may not be aware of all external integrations that its accounts still trust.
Attackers have consistently exploited vulnerabilities at these junctions. The European Commission experienced a breach through a security tool it employed for its defense, illustrating a similar issue on a different scale.
Neither company has identified the attackers or disclosed whether the accounts were specifically targeted or discovered randomly. Both investigations are still active, and more information about how the attackers identified and exploited the flaw is likely to surface.
For now, Dropbox has taken the usual approach organizations often adopt when an old integration becomes a security risk: it severed a connection that was no longer needed, a preventive measure that could have been implemented well before the breach occurred.
Other articles
Dropbox reports that 5,000 accounts were compromised via a Lenovo login.
Attackers created Lenovo IDs using the email addresses of victims and gained access to Dropbox accounts without needing a password. None of the accounts had multi-factor authentication enabled.
