Business

The Dropbox Breach Exposed a Third-Party Login Risk. Most Companies Have the Same Vulnerability

The attackers exploited a weakness in the file-sharing system. Experts say this exposes the hidden risks of third-party login systems.

The Dropbox Breach Exposed a Third-Party Login Risk. Most Companies Have the Same Vulnerability

Hackers didn’t need a Dropbox password to break into thousands of customer accounts. A Lenovo username and password was enough.

Dropbox confirmed this week that roughly 5,000 accounts were compromised last month, after hackers gained unauthorized access to the cloud-storage platform and viewed or downloaded content from some of those accounts.

Bloomberg first reported the breach earlier this week,

Bloomberg first reported the breach earlier this week, prompting Dropbox to confirm it publicly and email affected users to let them know their accounts had been accessed without authorization between August 4 and August 21.

According to the company, hackers reportedly accessed files in fewer than a third of the compromised accounts.

Refreshed leadership advice from CEO Stephanie Mehta

An Inc.com Featured Presentation

Dropbox said it identified unauthorized access affecting accounts linked to a Lenovo ID that didn’t have two-factor authentication enabled, essentially a security shortcut that let some users skip the usual extra login verification. 

Once discovered, Dropbox forced out all active sessions

Once discovered, Dropbox forced out all active sessions logged in through Lenovo ID, severed the connection between the IDs and Dropbox accounts entirely, and also updated its systems so that logging in through Lenovo now also requires entering a Dropbox password. The company said it has reported the incident to data-protection regulators.

Although Lenovo ID was the available rather than removing it entirely. Instead they added additional layering security. “We expired all sessions authenticated through Lenovo ID, severed any link between Lenovo and a user’s Dropbox account, and ensured no one can access Dropbox accountssaid

Source: www.inc.com

Show More

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button