ON
← Back to feed
Dropbox says about 5,000 accounts compromised in August hack
SG🏛️ PoliticsCenter22 hr. ago

Dropbox says about 5,000 accounts compromised in August hack

Dropbox announced that approximately 5,000 user accounts were compromised during a security breach in August. The breach occurred between August 4 and August 21, with some users receiving notifications from Dropbox about unauthorized access. Hackers accessed files in less than a third of the affected accounts. Dropbox attributed the breach to a legacy integration with Lenovo ID, which lacked two-factor authentication. The company took steps to secure its system by requiring users to input their Dropbox password before accessing accounts via Lenovo. Dropbox informed regulatory authorities about the incident, and Lenovo stated that its own customers were not impacted while investigating the issue.

Dropbox disclosed on Tuesday that approximately 5,000 user accounts were breached during a security incident in August, according to the company’s statement. The breach occurred between August 4 and August 21, with unauthorized individuals gaining access to some of the affected accounts and downloading stored content. The company informed users via email on Monday, confirming the breach following initial reports from Bloomberg News. The breach involved accounts associated with Lenovo IDs that lacked two-factor authentication. Dropbox stated that these accounts were vulnerable because they could be accessed without requiring additional verification steps. As a result, the company terminated all sessions authenticated using Lenovo IDs and took measures to prevent future unauthorized access. Users will now need to input their Dropbox password before logging into their accounts through Lenovo devices. In response to the breach, Dropbox has taken several steps to secure its system. It has severed the connection between Lenovo IDs and Dropbox accounts and modified its processes to ensure that users must enter their Dropbox password prior to accessing their accounts through Lenovo. These changes aim to close potential security gaps that could allow unauthorized access. Lenovo acknowledged the issue, identifying a "legacy integration" between its ID service and Dropbox that might have allowed improper authentication of certain Dropbox accounts. The company emphasized that its own customers were not impacted by the breach and that an investigation into the matter is still underway. Lenovo is working to understand how this integration could have posed a risk and is taking steps to address it. The security incident led to a decline in Dropbox's stock price, which dropped by roughly 2.4 percent in extended trading on Tuesday. This reflects investor concerns over the potential impact of the breach on the company’s reputation and financial stability. Dropbox has also notified relevant data protection authorities about the incident, as required under regulatory guidelines. Users who were affected by the breach were sent notifications by Dropbox, alerting them to the unauthorized access to their accounts. While the exact number of users whose files were accessed remains unclear, Dropbox indicated that less than a third of the compromised accounts had files accessed by the attackers. The company has not yet released further details regarding the extent of data exposure or the specific types of information that may have been accessed. The situation highlights the importance of multi-factor authentication in protecting online accounts from unauthorized access. Dropbox’s actions demonstrate a commitment to improving security measures, though the incident underscores broader challenges related to data privacy and cybersecurity. As investigations continue, both Dropbox and Lenovo are likely to provide more detailed updates on the matter in the coming weeks.

1 reports

Channel NewsAsia (CNA) logoChannel NewsAsia (CNA)State / PublicCenter22 hr. ago
Dropbox says about 5,000 accounts compromised in August hack

Dropbox announced that approximately 5,000 user accounts were compromised during a security breach in August. The breach occurred between August 4 and August 21, with some users receiving notifications from Dropbox about unauthorized access. Hackers accessed files in less than a third of the affected accounts. Dropbox attributed the breach to a legacy integration with Lenovo ID, which lacked two-factor authentication. The company took steps to secure its system by requiring users to input their Dropbox password before accessing accounts via Lenovo. Dropbox informed regulatory authorities about the incident, and Lenovo stated that its own customers were not impacted while investigating the issue.

Bias read (Center): The article presents a factual report on a cybersecurity incident involving Dropbox and Lenovo, focusing on technical details and corporate responses. There is no overt ideological framing, partisan emphasis, or editorialized commentary. The narrative remains neutral, balancing information about the

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories