Dropbox tightens security after 5,000-account breach

The unauthorised access took place between Aug. 4 and Aug. 21, Dropbox said. The company notified some affected users by email on Monday after identifying the breach.

Files were accessed in fewer than one-third of the compromised accounts, according to Dropbox. The affected accounts were linked to Lenovo IDs that did not have two-factor authentication enabled.

Dropbox has since terminated all sessions authenticated through Lenovo IDs and removed the link between Lenovo IDs and Dropbox accounts. It also updated its systems to require users to enter their Dropbox passwords before accessing accounts through Lenovo.

Lenovo said it had identified a legacy integration between Lenovo ID and Dropbox that could have been used to improperly authenticate certain Dropbox accounts. The company said its own customers were not affected and that an investigation was continuing.

Dropbox said it had reported the incident to data protection regulators. Its shares fell about 2.4% in extended trading on Tuesday following news of the breach.

The incident highlights the security risks associated with third-party authentication systems and the importance of additional safeguards such as two-factor authentication. – TS/ERMD

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top