Dropbox is notifying users of unauthorized account access resulting from an email verification vulnerability in Lenovo's identity system. Attackers exploited the flaw to create fraudulent Lenovo IDs and gain entry to Dropbox accounts.
Dropbox disclosed a security incident affecting some of its users after attackers leveraged a flaw in Lenovo's email verification process. The breach occurred when bad actors used the vulnerability to register unauthorized Lenovo IDs, which they then used to access Dropbox accounts.
The attack chain exploited how Lenovo verified email addresses during account creation. By circumventing this validation process, attackers could create fake Lenovo accounts using email addresses tied to existing Dropbox users. This allowed them to gain unauthorized access without requiring the victims' passwords.
Dropbox stated it discovered the unauthorized access through its security monitoring systems and began notifying affected users. The company has not disclosed the exact number of compromised accounts but confirmed that a specific subset of users experienced unauthorized access.
In response, Dropbox recommended that users take standard security measures including changing passwords, reviewing account activity, and enabling two-factor authentication. The service also stated it has been working with Lenovo to address the underlying vulnerability in their email verification system.
Lenovo has not issued a separate public statement as of this report. The incident underscores how vulnerabilities in third-party services can create cascading security risks for other platforms, particularly when account linkage or single sign-on features are involved.
This breach adds to a growing list of recent account compromises affecting major tech platforms. Users are increasingly advised to maintain unique, strong passwords across services and activate multi-factor authentication wherever available to mitigate the impact of third-party vulnerabilities.
Dropbox users should monitor their accounts for suspicious activity and consider reviewing connected applications and devices with account access.
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin exposes WordPress sites to remote code execution and complete takeover by unauthenticated attackers.
An identity theft search site claimed to possess over 150 million driver's license photos stolen from a major ID verification service. The crime site has since been shut down.
Iran-linked hackers have compromised approximately 100 American water utilities in a sustained campaign targeting critical infrastructure. The EPA is allocating $11 million in funding to strengthen cybersecurity defenses across water systems.
Attackers exploited BGP routing vulnerabilities to redirect Virtualizor VPS management software update requests to malicious servers. The compromise affected users attempting to download legitimate updates for the widely-used hosting control panel.