Tertius News is an AI-native newsroom: an AI model reads the linked source articles below and extracts what each outlet reported, so you can compare their coverage side by side. How this works →
Dropbox breach compromises 5,000 accounts via Lenovo ID loophole
Dropbox said about 5,000 accounts were compromised last month after hackers exploited a flaw in Lenovo's authentication system. The company has terminated affected sessions, removed links between the services, and notified regulators.
By Tertius News AI Desk3 distinct · 3 mastheads · 3 articlesVersion 2Coverage Published
Breach Details
Dropbox announced on Tuesday that around 5,000 accounts were compromised last month, with hackers viewing and downloading content stored on the cloud-storage platform. The unauthorized access occurred between August 4 and August 21, according to notification emails sent to affected users and reported by Reuters and Bloomberg.
The company said the affected accounts were linked to Lenovo IDs and were not protected by multi-factor authentication. Hackers exploited an issue with Lenovo's email verification process to create Lenovo IDs using the email addresses of Dropbox users who had not signed up for the service, according to notification emails seen by Bloomberg News.
In fewer than a third of the compromised accounts did hackers actually access files, Dropbox said.
Response and Remediation
Dropbox said it has terminated all sessions authenticated through Lenovo ID, removed the links between the two services, and changed its systems to require users to enter their Dropbox password when accessing an account through Lenovo. A Dropbox spokesman told Bloomberg that the company moved to secure affected accounts after discovering the breach and has notified regulators and affected users.
Lenovo acknowledged a "legacy integration" with Dropbox that "could be used to improperly authenticate certain Dropbox accounts." The company said its own customers were not affected and that it was working with Dropbox to mitigate the risk while its investigation continues.
Market Reaction
Shares of Dropbox fell around 2.4% in extended trading on Tuesday following the news.
How each outlet told it
A framing line is our reading of that outlet's own text — an interpretation, not a quotation and not a fact we assert. Check it against what the outlet published.
Framing: The headline emphasizes the scale of the breach (5,000 accounts) and the specific loophole through Lenovo’s ID system.
Facts Included:
Dropbox accounts were compromised last month after hackers exploited a flaw involving Lenovo’s account authentication system
Hackers viewed and downloaded files from roughly 5,000 accounts during unauthorised access between August 4 and August 21
The affected accounts were not protected by multi-factor authentication and were linked to Lenovo IDs
Hackers exploited an issue with Lenovo’s email verification process to create Lenovo IDs using the email addresses of Dropbox users who had not signed up for the service
Dropbox said it has since terminated all sessions authenticated through Lenovo ID, removed the links between the two services and changed its systems to require users to enter their Dropbox password when accessing an account through Lenovo
A Dropbox spokesman told Bloomberg that the company moved to secure affected accounts after discovering the breach and has notified regulators and affected users
Lenovo said it recently identified a “legacy integration” with Dropboxthat “could be used to improperly authenticate certain Dropbox accounts”
The company said its own customers were not affected and that it was working with Dropbox to mitigate the risk while its investigation continues
Framing: The headline emphasizes the breach of Dropbox accounts by hackers and their access to user data.
Facts Included:
Hackers breached Dropbox accounts by exploiting a Lenovo ID, which is a username and password combination used to log into products and services offered by Lenovo Group Ltd.
Attackers were able to create Lenovo IDs using the email addresses of Dropbox users due to an 'issue' with Lenovo's email verification process, according to Dropbox's notification emails.
Lenovo acknowledged a 'legacy integration' between Lenovo ID and Dropbox that could be exploited for unauthorized access.
Lenovo said it is working with Dropbox to address the issue.
Lenovo's customers were not affected by this security incident, and an investigation into the matter is still ongoing.
Framing: Dropbox says about 5,000 accounts compromised in August hack
Facts Included:
Around 5,000 accounts were compromised last month, with hackers viewing and downloading content stored on the cloud-storage platform
Some Dropbox users received an email from the company on Monday notifying them that their accounts have been accessed without authorization between August 4 and August 21
Dropbox confirmed after Bloomberg News reported the hack earlier in the day
Hackers accessed files in fewer than a third of the compromised accounts
Shares of Dropbox fell around 4% in extended trading on Tuesday
Dropbox told Reuters that it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, prompting the company to terminate all sessions authenticated through a Lenovo ID
The company has removed any links between Lenovo IDs and Dropbox accounts and changed its systems so that users must enter their Dropbox password before accessing an account through Lenovo
Dropbox said it had reported the incident to data protection regulators
AI-extracted; can misattribute a claim — see Methodology.
Each row is one claim, attributed to the outlet whose wording states it most clearly. Confidence rates how directly the source text states the claim — explicit and unhedged rates high; hedged, pieced-together, or internally inconsistent statements rate lower. It does not measure whether the claim is true. Status is Contested when two claims on this page negate each other; otherwise it counts the distinct outlets we found asserting that specific claim — so a single-source claim can still show high confidence, and a multi-source claim can show medium. Every one of those outlets is named beside the status, so you can check the count against the list. For claims extracted before we began storing that list, the row says so: it names the outlet the claim is quoted from and states that we have not recorded which outlets backed it. Outlets wrote at different times, so a figure that evolves — a casualty count, for example — can legitimately differ between rows; check the "as of" time next to each claim's source.
Claim
Confidence
Status
ClaimAround 5,000 Dropbox accounts were compromised last month, with hackers viewing and downloading content stored on the cloud-storage platform.
ConfidenceHigh
StatusMulti-source (2 outlets · 2 distinct) via Rappler , Malay Mail
ClaimSome Dropbox users received an email from the company on Monday notifying them that their accounts were accessed without authorization between August 4 and August 21.
ClaimDropbox told Reuters that it identified unauthorized access affecting accounts linked to a Lenovo IDthat did not have its two-factor authentication enabled.
ClaimHackers breached Dropbox accounts by exploiting a Lenovo ID, which is a username and password combination used to log into products and services offered by Lenovo Group Ltd.
ClaimAttackers were able to create Lenovo IDs using the email addresses of Dropbox users due to an 'issue' with Lenovo's email verification process, according to Dropbox's notification emails.
ClaimA Dropbox spokesman told Bloomberg that the company moved to secure affected accounts after discovering the breach and has notified regulators and affected users.