Dropbox says about 5,000 accounts compromised in August hack
Summarized by DistantNews. Read the original for the full story.
At a glance
- Dropbox said hackers compromised about 5,000 accounts between Aug. 4 and Aug. 21, and accessed files in fewer than one-third of them.
- The affected accounts were linked to Lenovo IDs without two-factor authentication; Dropbox ended those sessions, removed the link and reported the incident to regulators.
- Lenovo described the problem as a legacy integration that could improperly authenticate some Dropbox accounts and said its own customers were not affected.
Dropbox said about 5,000 accounts were compromised in an August hack, with attackers viewing and downloading content stored on the cloud platform.
The company said some users received notices about unauthorized access between Aug. 4 and Aug. 21. Hackers accessed files in fewer than one-third of the affected accounts.
legacy integration
Dropbox traced the unauthorized access to accounts linked to Lenovo IDs that did not have two-factor authentication enabled. It terminated all sessions authenticated through a Lenovo ID, removed the links between Lenovo IDs and Dropbox accounts, and changed its systems to require users to enter their Dropbox password before accessing an account through Lenovo.
Dropbox reported the incident to data-protection regulators. Lenovo said it had identified a โlegacy integrationโ that โcould be used to improperly authenticate certain Dropbox accounts,โ while saying its own customers were not affected and that its investigation continued. Dropbox shares fell about 2.4% in extended trading.
could be used to improperly authenticate certain Dropbox accounts
Originally published by CNA. Summarized and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.