
Dropbox is warning about 5,000 users that attackers have accessed their accounts without using a password.
The company says the access ran from August 4th to August 21st and hit only accounts that did not use multi-factor authentication, reports Reuters.
Dropbox had a shortcut that let people open their files with a Lenovo login instead of a Dropbox password.
Attackers were able to create Lenovo logins with Dropbox users’ email addresses, and Lenovo did not check those emails well enough.
Dropbox then treated that Lenovo login as the real user, even if the person had never used a Lenovo product.
Files were viewed or downloaded from about 1,500 of the accounts.
Dropbox cut off those login sessions, turned off the Lenovo sign-in option and now requires a Dropbox password. It has emailed the people affected and told regulators. The company says it does not expect a material hit to the business.
Lenovo says the problem was a “legacy integration” that “could be used to improperly authenticate certain Dropbox accounts.” It says its own users are not affected and that its investigation is still open.
Follow us on X, Facebook and Telegram
Don't Miss a Beat – Subscribe to get email alerts delivered directly to your inbox
The post Dropbox Says Hackers Accessed About 5,000 Accounts Without Passwords appeared first on The Daily Hodl.