5,000 Dropbox accounts were compromised in August after attackers exploited a weakness in the way Lenovo IDs were linked to the cloud-storage service.
Dropbox said the unauthorised access took place between 4th and 21st August, with attackers able to view accounts and, in some cases, download stored files.
The company told Reuters files were accessed in fewer than a third of the affected accounts, which we're sure will be very reassuring to those whose data was breached.
A flaw in Lenovo's email verification process enabled the attack. A threat actor could leverage this to create a fraudulent Lenovo ID using another person's email address.
They could then use the bogus ID to access the Dropbox account linked to that email address, without knowing the user's Dropbox password.
The issue stemmed from Dropbox's authentication infrastructure and did not depend on users having an existing Lenovo account.
Dropbox relies on Lenovo Identity Provider Services within its authentication system, allowing users to access their Dropbox accounts through verified Lenovo IDs.
However, the account-linking mechanism trusted Lenovo's assertion that the person creating the Lenovo ID had control of the email address. It did not require that person to prove their identity through the existing Dropbox login system.
Dropbox told affected users that an "issue with Lenovo's email verification process" had allowed an unauthorised party to register a Lenovo ID using their email address and subsequently access the corresponding Dropbox account.
Lenovo describes flaw as a legacy integration
Lenovo said the problem involved a legacy integration between Lenovo ID and Dropbox that could be used to improperly authenticate some Dropbox accounts.
"Upon identifying the issue, Dropbox and Lenovo worked collaboratively to promptly mitigate the risk," a Lenovo spokesperson said .
The company said its own customers were not affected by the incident.
Some Dropbox users said they had received warnings suspicious sign-ins roughly two weeks before the company disclosed the wider breach.
Some responded by changing their passwords and enabling two-factor authentication.
Dropbox has since invalidated all sessions that were authenticated through Lenovo IDs. It has also introduced an additional safeguard requiring users to enter their Dropbox password when attempting to sign in through Lenovo ID.
Legacy systems can create hidden security risks
The incident shows there is a broader security problem for organisations that rely on multiple identity and single sign-on systems.
The breach did not depend on a conventional vulnerability in Dropbox itself. Instead, attackers exploited the trust between two services and a longstanding integration that allowed one system to authenticate users for another.
Such arrangements can remain in place for years, even as the security assumptions behind them change.
Describing an integration as "legacy" can also mean that it continues to operate because removing it could disrupt existing services.
The 17-day period during which attackers were able to access accounts is also telling; the unauthorised activity was not detected by monitoring system, but through a post-breach investigation.
The incident illustrates the need to keep track of which external identity providers your cloud services trust.
An organisation may secure its Dropbox accounts with strong passwords and multi-factor authentication, for example, while overlooking an older third-party authentication route that provides another way into those accounts.
The investigation into the incident remains under way, and neither company has said who was behind the attack or how the attackers discovered the weakness.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
