Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs.
Although some affected users did not have Lenovo accounts, the cloud-storage provider said it uses Lenovo Identity Provider Services as part of its authentication infrastructure. This allows users to log into Dropbox accounts using verified Lenovo IDs.
According to the notification sent to impacted users, the unauthorized access was possible due to "an issue with Lenovo's email verification process," which "allowed an unauthorized party to register a Lenovo ID using your email address."
The attacker then used the fraudulent Lenovo ID to access the Dropbox account registered under the same email address without needing the login password.
Dropbox’s identity-linking process trusted Lenovo’s assertion that the attacker controlled the email address without requiring confirmation through the existing Dropbox login method.
“While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.”
Dropbox's notice to impacted users
Source: @yonilevy
Some Dropbox users reported receiving "about two weeks ago" notifications about suspicious Dropbox sign-ins and immediately changing their password and activating two-factor authentication (2FA).
"One odd thing at the time: the Dropbox login page had started offering 'Continue with SSO' for my email even though I never created a Lenovo ID," user xaphod said.
... continue reading