Dropbox said that around 5,000 accounts were compromised last month, with hackers viewing and downloading content stored on the cloud-storage platform. A few Dropbox users received an email from the company notifying them that their accounts have been accessed without authorization between August 4 and August 21.
The company said that hackers accessed files in fewer than a third of the compromised accounts. After the revelation, shares of Dropbox fell around 2.4% in extended trading on Tuesday.
Dropbox told Reuters that it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, prompting the company to terminate all sessions authenticated through a Lenovo ID.
The company has removed any links between Lenovo IDs and Dropbox accounts and changed its systems so that users must enter their Dropbox password before accessing an account through Lenovo.
Dropbox is said to have already reported the incident to data protection regulators.
Lenovo identified a "legacy integration" between Lenovo ID and Dropbox that "could be used to improperly authenticate certain Dropbox accounts". The company said its own customers were not affected and that an investigation was ongoing.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




