Dropbox Hack: Around 5,000 Accounts Compromised, Hackers Accessed And Downloaded Files

dropbox hack: around 5,000 accounts compromised, hackers accessed and downloaded files

The US-based popular cloud storage service Dropbox has revealed that around 5,000 user accounts were compromised in a cyberattack last month. According to the company, hackers accessed and downloaded files stored on the cloud platform.

The company said the unauthorised access took place between August 4 and August 21, affecting accounts connected to Lenovo IDs that did not have two-factor authentication enabled.

According to Reuters, the cloud storage platform confirmed that hackers were able to access files in fewer than one-third of the affected accounts.

Dropbox has since taken steps to block the attack. The company terminated all sessions that were authenticated through Lenovo ID and removed the connection between Lenovo IDs and Dropbox accounts, the report said.

The company has also changed its systems so users will now need to enter their Dropbox password before they can access an account through Lenovo.

The incident seems to be linked to an old connection between Lenovo’s identity system and Dropbox. Lenovo said it had identified a ‘legacy integration’ that could be used to improperly authenticate certain Dropbox accounts.

Lenovo, however, said its own customers were not affected and that its investigation into the incident is still underway.

According to the report, the breach has raised fresh concerns for Dropbox users who rely on the platform to store personal and work-related files online.

Dropbox said it has also reported the incident to data protection regulators. The company has not disclosed exactly what types of files were accessed or downloaded from the affected accounts.

For users, the incident is another reminder of the importance of two-factor authentication and regularly reviewing connected accounts and third-party login options.

While the company said only a portion of the compromised accounts had files accessed, the incident shows how older integrations between different services can create security risks.

source

Leave a Reply