Dropbox Recently, some users were notified that from August 4th to August 21st, unauthorized individuals took advantage of a security vulnerability related to Lenovo ID to log into their accounts. The company stated that no widespread leakage of files was detected during the investigation, but it has been found that some files on these accounts have been viewed or downloaded.
The vulnerability lies in the Lenovo ID verification process.
According to Dropbox, the issue lies in the single-sign-on integration process between it and Lenovo ID. Due to a flaw in the email verification mechanism of Lenovo, attackers can register for Lenovo ID using someone else's email address, and then use this to log in to the Dropbox account associated with that email.
A company spokesperson stated that the affected accounts were all associated with Lenovo ID and did not have double authentication enabled for Dropbox itself. The attack process did not require the victims to provide the password for Dropbox nor did it necessitate control over their email addresses.
Approximately 5,000 accounts are affected.
According to Dropbox, approximately 5,000 accounts were affected, with less than one-third of these accounts experiencing file viewing or downloading. The company has sent emails to all affected users and has adjusted the way in which Lenovo ID accesses Dropbox accounts.
An affected user publicly shared a screenshot of the Dropbox notification on the X platform. The screenshot shows that their account was logged in on August 18th near Canary Wharf in London, UK, using a Chrome browser on a Windows device. The user stated that they have not registered for a Lenovo account and have never been to the UK.
Platform account security incidents continue to attract attention.
Dropbox indicates that if a user has not received an official notification email, then their account is not within the scope of impact of this event. The company also recommends that users with any questions regarding their account activities contact the support team.
This incident has once again drawn external attention to the security of accounts on large internet platforms. Just this week, users on platform X also reported receiving abnormal password reset emails, notifications of unfamiliar logins, and account lockouts. X subsequently stated that no new evidence of data leakage has been found.












