Some customers are being alerted by Dropbox that an unauthorized person gained access to their accounts by registering false Lenovo IDs by taking advantage of a weakness in Lenovo’s email verification procedure.
The cloud storage service claimed to employ Lenovo Identity service Services as part of its authentication architecture, despite the fact that some impacted users did not have Lenovo accounts. This enables users to utilize validated Lenovo IDs to access Dropbox accounts.
A problem with Lenovo’s email verification procedure “allowed an unauthorized party to register a Lenovo ID using your email address,” according to the message provided to affected users, made the illegal access feasible. The attacker then gained access to the Dropbox account linked to the same email address without requiring the login password by using the fictitious Lenovo ID.
Lenovo’s claim that the attacker was in charge of the email address was trusted by Dropbox’s identity-linking mechanism, which did not require confirmation using the current Dropbox login method read more about Dropbox accounts breached through Lenovo email verification flaw
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
