Dropbox Authentication Vulnerability Leads to Abnormal Access to Approximately 5,000 Accounts
Coinpaper
44m ago
Ai Focus
Dropbox reveals that attackers took advantage of a verification vulnerability in Lenovo ID to access approximately 5,000 accounts abnormally. The company states that the relevant login method has been fixed.
Helpful
No.Help

Dropbox Recently, some users were notified that from August 4th to August 21st, unauthorized individuals took advantage of a security vulnerability related to Lenovo ID to log into their accounts. The company stated that no widespread leakage of files was detected during the investigation, but it has been found that some files on these accounts have been viewed or downloaded.

The vulnerability lies in the Lenovo ID verification process.

According to Dropbox, the issue lies in the single-sign-on integration process between it and Lenovo ID. Due to a flaw in the email verification mechanism of Lenovo, attackers can register for Lenovo ID using someone else's email address, and then use this to log in to the Dropbox account associated with that email.

A company spokesperson stated that the affected accounts were all associated with Lenovo ID and did not have double authentication enabled for Dropbox itself. The attack process did not require the victims to provide the password for Dropbox nor did it necessitate control over their email addresses.

Approximately 5,000 accounts are affected.

According to Dropbox, approximately 5,000 accounts were affected, with less than one-third of these accounts experiencing file viewing or downloading. The company has sent emails to all affected users and has adjusted the way in which Lenovo ID accesses Dropbox accounts.

An affected user publicly shared a screenshot of the Dropbox notification on the X platform. The screenshot shows that their account was logged in on August 18th near Canary Wharf in London, UK, using a Chrome browser on a Windows device. The user stated that they have not registered for a Lenovo account and have never been to the UK.

Platform account security incidents continue to attract attention.

Dropbox indicates that if a user has not received an official notification email, then their account is not within the scope of impact of this event. The company also recommends that users with any questions regarding their account activities contact the support team.

This incident has once again drawn external attention to the security of accounts on large internet platforms. Just this week, users on platform X also reported receiving abnormal password reset emails, notifications of unfamiliar logins, and account lockouts. X subsequently stated that no new evidence of data leakage has been found.

Tip
$0
Like
0
Save
0
Views 15
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: After X Money went live, users' accounts were targeted by attackers
It is indicated that after the launch of X Money, attackers triggered the password reset process in bulk, but no evidence of a system breach has been found yet.
TechCrunch
·2026-09-02 05:13:03
8
Anthropic releases Claude Fable 5.1, with significantly improved benchmark scores
Anthropic Launches Claude Fable 5.1; the new model has seen significant improvements in scientific research and end-user coding tests compared to its predecessor, and has already been integrated with Claude API as well as several other cloud platforms.
Coinpaper
·2026-09-02 04:10:12
22
Anthropic releases Fable 5.1: Reducing costs and relaxing restrictions
Anthropic releases Fable 5.1 and Mythos 5.1; the new versions reduce costs, minimize misjudgment limitations, and promote high-privacy local deployment services.
TechCrunch
·2026-09-02 03:58:08
19
Ethereum: Bitcoin rebounds after falling below $77,000; Oil prices put pressure on the crypto market
The US-Iran conflict drives up oil prices and US Treasury yields; Bitcoin briefly fell below $77,000, and the net inflow of ETF in spot markets failed to reverse the short-term downward trend.
Coinpaper
·2026-09-02 03:20:16
26
U.S.-Iranian clashes drive up oil prices, putting pressure on U.S. tech stocks
The escalation of tensions between the US and Iran drives up oil prices and US Treasury yields; tech stocks weaken, while energy stocks benefit.
Coinpaper
·2026-09-02 03:20:13
22
View More