• Over 5,000 Dropbox accounts have been hacked, and the attackers o

    From TechnologyDaily@1337:1/100 to All on Wednesday, September 02, 2026 19:15:24
    Over 5,000 Dropbox accounts have been hacked, and the attackers only needed
    an email address

    Date:
    Wed, 02 Sep 2026 18:05:00 +0000

    Description:
    A bug in Lenovo's ID verification system made it possible to access Dropbox accounts, but the bug has since been fixed.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Hackers exploited Lenovos
    flawed email verification to hijack ~5,000 Dropbox accounts Attackers created Lenovo IDs with victims emails, bypassing login; 2FA absence worsened impact Dropbox ended Lenovo ID logins, expired sessions, and urged password changes plus 2FA setup Around 5,000 Dropbox user accounts were compromised when hackers found a vulnerability in the Lenovo ID verification process. What
    does a Lenovo flaw have to do with peoples Dropbox accounts, you might ask? Here is what happened:

    Earlier this week, Dropbox started notifying affected individuals about the incident. In the data breach notification email, the company explains:
    Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have
    an existing Lenovo ID, our investigation determined that an issue with
    Lenovos email verification process allowed an unauthorized party to register
    a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address. Latest Videos From TechRadar Watch full video here: Fixing the flaw In other words, all
    criminals needed to have to pull this off was peoples email addresses. Using that information, they created Lenovo IDs and simply waltzed right into Dropbox accounts.

    The attack took place between August 4 and 21, the company further said, adding that most of the accounts that were accessed did not have 2FA enabled. In around a third of them, there is evidence stored documents were either viewed or downloaded. You may like Meta reveals over 20,000 Instagram
    accounts hacked and stolen using AI support bot 81 million login attempts hit Microsoft 365 accounts as hackers try password-spraying to force entry The Vimeo breach and the dangers of delegated trust

    The vulnerability has since been addressed, and further steps taken to
    protect Dropbox users privacy. The company said it promptly expired all sessions logged in through Lenovo IDs, and terminated all links between
    Lenovo and Dropbox accounts. Now, it made it mandatory to submit a password when logging in through a Lenovo ID.

    No one can access your Dropbox account via a Lenovo ID without first entering your Dropbox password, it said. Still, it urged users to change their passwords, enable two-step verification, and change the password for their email accounts. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, thats an indefensible gap and its one that users could have closed themselves regardless of what Lenovo or Dropbox did or didnt do with their legacy integration," said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.

    "The combination of an unreviewed third-party authentication pathway and accounts without MFA is essentially an open invitation. The practical lesson is straightforward and applies well beyond this specific incident. Every organisation and every individual should periodically audit what third-party services have authentication access to their accounts. OAuth grants, SSO connections, and third-party login integrations accumulate silently and
    rarely get removed when the relationship that created them ends.

    Via Cybernews The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/over-5-000-dropbox-accounts-have-been-h acked-and-the-attackers-only-needed-an-email-address


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)