Dropbox disclosed on September 1 that around 5,000 user accounts had been logged into by unauthorized parties. The attackers never needed a Dropbox password. They walked in through the account linking between Dropbox and Lenovo ID, Lenovo's authentication service. The intrusions took place between August 4 and August 21, and in fewer than a third of the affected accounts, stored files were viewed or downloaded.
How the break-in worked without a password
What stands out here is that nothing was cracked on the Dropbox side. No password was brute-forced, and no credential reuse was exploited. The way in was the authentication link between Lenovo ID and Dropbox.
The root of the problem sat in Lenovo's email verification process. Normally, registering a Lenovo ID with a given email address requires proving you own that address. That check was insufficient, so an outsider could register a Lenovo ID using someone else's email address.
The rest was straightforward. Signing in to Dropbox with that fraudulent Lenovo ID dropped the attacker into the existing Dropbox account tied to the same address. No password guessing, no phishing. An account on an outside service effectively worked as a spare key to a Dropbox account.
Which accounts were exposed
The accounts affected were those that could authenticate through Lenovo ID and did not have Dropbox two-factor authentication turned on. Put another way, accounts with two-factor authentication enabled were stopped at the final gate even when this path was taken.
Dropbox says that in fewer than a third of the roughly 5,000 accounts, stored files were actually viewed or downloaded. The rest were entered but the contents were not touched. Given what people keep in cloud storage, though, this is not a matter that the affected users will weigh by headcount.
What Dropbox and Lenovo did
Dropbox fixed the issue and expired every existing session that had been authenticated through Lenovo ID. For the affected accounts it severed the Lenovo link entirely, and any future authentication via Lenovo ID now requires the Dropbox password. The company has notified affected users and regulators, and does not expect a material impact on its business.
Lenovo acknowledged the problem as well. It explained that the legacy design of the Lenovo ID and Dropbox integration left some Dropbox accounts open to improper authentication. Lenovo says its own customers were not affected, and the investigation is continuing.
The blind spot that comes with convenience
Signing in with an outside identity is convenient because it spares you another password to remember. It also means the strength of your account is decided by the strength of the service you linked it to. When the partner's email verification is loose, as it was here, a well-built service can still be undone from that direction.
These links also tend to be set up once and then forgotten for years. A connection you assume you stopped using may still be sitting there as a working spare key. Two practical steps help: turn on two-factor authentication for your main cloud services, and open the list of connected services in your account settings and revoke anything you do not recognize.
Summary
The unauthorized logins to roughly 5,000 Dropbox accounts did not come from leaked passwords. They came in sideways, through the authentication link with Lenovo ID. The conditions for exposure were an account reachable via Lenovo ID with two-factor authentication switched off, which also shows that two-factor authentication held as the last line of defense. Both companies have already revised and repaired the integration, but the question of how far to trust an external identity link is one that users are left to answer for themselves.
