Dropbox logo
Somebody registered a Lenovo ID using a stranger’s email address and then used it to sign into that person’s Dropbox account without needing their password. About 5,000 accounts were compromised between August 4 and 21, Dropbox said.
The flaw was in a legacy integration between Lenovo ID and Dropbox that did not properly verify email ownership. Registering an account with someone else’s address was enough to authenticate as that person.
Files were viewed or downloaded in fewer than a third of the affected accounts. That means roughly 3,500 accounts were accessed without anything being taken, although the numbers alone do not show whether attackers were looking for specific files or simply accessing accounts automatically.
Every compromised account lacked multi-factor authentication. Dropbox has been clear about that, and it is probably the most useful detail for anyone looking at what could have prevented the attack.
Lenovo identified the integration on its side and said its own customers were unaffected. The vulnerability existed in the connection between the two systems rather than within either service itself.
Dropbox has since terminated every session authenticated through Lenovo ID, disabled the integration entirely, and now requires a native Dropbox password before an account can be accessed. Affected users were emailed on Monday.
Multi-factor authentication would have stopped the attack because the flaw effectively bypassed the password, leaving no second layer of authentication. It is the fairly unglamorous lesson in an otherwise unusual breach.
Both companies have reported the incident to data protection regulators, and investigations are continuing. For European users, that brings GDPR notification obligations, including the 72-hour deadline that applies once an organisation becomes aware of a qualifying breach.
Shares fell about 2.4% in extended trading, a relatively modest reaction to a breach involving 5,000 accounts at a company with hundreds of millions of users.
What makes the incident interesting is the shape of the attack rather than its size. This was not a Dropbox vulnerability or a Lenovo vulnerability in isolation, but an old trust relationship between the two systems that had not been revisited.
The 17-day window is also notable. The access between August 4 and 21 was not detected through monitoring on either side, but uncovered through an investigation afterwards.
Single sign-on integrations tend to accumulate quietly and rarely get removed. Each creates another route into an account that does not depend on the account’s own password, often based on security assumptions that made sense when the integration was first built.
The word “legacy” is doing a lot of work in both companies’ explanations. In practice, it often describes a system that is still running because turning it off could break something, even if nobody is particularly interested in maintaining it.
For enterprise customers, there is a practical question here. A company storing business documents in Dropbox and using SSO through a hardware vendor’s identity system may not know every external integration its accounts still trust.
Attackers have repeatedly found weaknesses at these seams. The European Commission was breached through a security tool it used to protect itself, which is the same type of problem at a different scale.
Neither company has attributed the attack or said whether the accounts were specifically targeted or discovered automatically. Both investigations are still open, and that is where more details about how the attackers found and used the flaw are likely to emerge.
For now, Dropbox has applied the remedy organisations often reach after an old integration becomes a security problem: it cut a connection that was no longer necessary, something that could have been done long before it was exploited.
Get the TNW newsletter
Get the most important tech news in your inbox each week.