SAN FRANCISCO, Sept 2 — Online file storage and sharing service Dropbox accounts were compromised last month after hackers exploited a flaw involving Lenovo’s account authentication system, with files accessed in some cases.
Dropbox said hackers viewed and downloaded files from roughly 5,000 accounts during unauthorised access between August 4 and August 21, international newswires Reuters and Bloomberg reported today.
The company said the affected accounts were not protected by multi-factor authentication and were linked to Lenovo IDs, which can be used to access Dropbox accounts.
Hackers exploited an issue with Lenovo’s email verification process to create Lenovo IDs using the email addresses of Dropbox users who had not signed up for the service, according to notification emails sent to affected users and seen by Bloomberg News.
Dropbox said it has since terminated all sessions authenticated through Lenovo ID, removed the links between the two services and changed its systems to require users to enter their Dropbox password when accessing an account through Lenovo.
A Dropbox spokesman told Bloomberg that the company moved to secure affected accounts after discovering the breach and has notified regulators and affected users.
Lenovo said it recently identified a “legacy integration” with Dropbox that “could be used to improperly authenticate certain Dropbox accounts”.
The company said its own customers were not affected and that it was working with Dropbox to mitigate the risk while its investigation continues.