Dropbox Accounts Compromised via Lenovo ID Verification Flaw
Cloud storage giant **Dropbox** has alerted thousands of users that their accounts were accessed by an unauthorized party. The breach exploited a critical flaw in **Lenovo**'s email verification process, allowing attackers to register fraudulent **Lenovo IDs** and bypass traditional login security for linked **Dropbox** accounts.
Cloud storage provider **Dropbox** is currently notifying a subset of its users about unauthorized access to their accounts. The breach was facilitated by a vulnerability within **Lenovo**'s email verification process, which **Dropbox** utilizes as part of its authentication infrastructure.
### The Vulnerability Explained
The core of the issue lies in a legacy integration between **Lenovo ID** and **Dropbox**. According to **Dropbox**'s notice to impacted users, an "issue with **Lenovo**'s email verification process" allowed an attacker to register a **Lenovo ID** using a victim's email address, even if the victim didn't have an existing **Lenovo** account. This fraudulent **Lenovo ID** was then used to log into the corresponding **Dropbox** account without requiring the **Dropbox** password.
**Dropbox**'s identity-linking process implicitly trusted **Lenovo**'s assertion that the attacker controlled the email address, effectively circumventing the need for direct confirmation through the existing **Dropbox** login method.

### Timeline and Impact
**Dropbox** determined that the unauthorized access occurred between August 4 and August 21. Reports from users, such as **xaphod** on Hacker News, indicate that some received suspicious sign-in notifications approximately two weeks prior to the public disclosure, prompting immediate password changes and the activation of two-factor authentication (2FA).
Approximately 5,000 accounts were reportedly accessed, with the attacker viewing and downloading content from some of these compromised accounts, as reported by **Reuters**.

*Source: @yonilevy*
### Lenovo's Response and Mitigation
**Lenovo** confirmed the issue, stating it was related to a "legacy integration between **Lenovo ID** and **Dropbox**" that could be leveraged "to improperly authenticate certain **Dropbox** accounts." Both companies reportedly worked collaboratively to mitigate the risk promptly.
**Lenovo** has clarified that its own customers were not affected by this specific issue. **Dropbox** has responded by expiring all sessions authenticated through **Lenovo IDs** and has implemented a new security measure: users attempting to log in via **Lenovo ID** authentication must now also enter their **Dropbox** account password.
This incident highlights the inherent risks in federated identity management and the critical importance of robust verification processes, even when integrating with trusted third-party services.