Dropbox Data Breach: 5,000 Accounts Compromised

An unauthorized party accessed certain Dropbox accounts by leveraging a flaw in the email verification process for Lenovo, enabling them to register false Lenovo IDs.
Dropbox uses the service as part of the authentication infrastructure, allowing users to log in with verified Lenovo IDs. Even users without Lenovo accounts may have been impacted, as the unauthorized party could have registered a Lenovo ID using the victim's email address, thus logging into the associated Dropbox account.
Reuters reports around 5,000 accounts were impacted. Spokesperson Tim Rathschmidt stated the compromised accounts did not have multi-factor authentication. On Tuesday, Dropbox shares decreased around 2.4%.
Brian Higgins, Security Specialist at Comparitech, comments, “Dropbox has been successfully infiltrated more than once in the past. It’s notable that they are blaming affected account holders for lackadaisical independent security measures which could be an emerging trend for victim organisations.
“What also draws attention is the focus on share price fluctuations peri and post breach. Most companies of commensurate size tend to see a swift bounce-back so it’s worth monitoring the markets for a day or two for any ‘material impact’ on their business.
“Unfortunately for anyone affected Tim Rathschmid’s employers fall in to the ‘too big to be bothered’ club. It’s doubtful there will be any notable fallout from this incident but it stands as a salutary tale for anyone who still doesn’t have 2FA.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!






