Breach Details

Dropbox announced on Tuesday that around 5,000 accounts were compromised last month, with hackers viewing and downloading content stored on the cloud-storage platform. The unauthorized access occurred between August 4 and August 21, according to notification emails sent to affected users and reported by Reuters and Bloomberg.

The company said the affected accounts were linked to Lenovo IDs and were not protected by multi-factor authentication. Hackers exploited an issue with Lenovo's email verification process to create Lenovo IDs using the email addresses of Dropbox users who had not signed up for the service, according to notification emails seen by Bloomberg News.

In fewer than a third of the compromised accounts did hackers actually access files, Dropbox said.

Response and Remediation

Dropbox said it has terminated all sessions authenticated through Lenovo ID, removed the links between the two services, and changed its systems to require users to enter their Dropbox password when accessing an account through Lenovo. A Dropbox spokesman told Bloomberg that the company moved to secure affected accounts after discovering the breach and has notified regulators and affected users.

Lenovo acknowledged a "legacy integration" with Dropbox that "could be used to improperly authenticate certain Dropbox accounts." The company said its own customers were not affected and that it was working with Dropbox to mitigate the risk while its investigation continues.

Market Reaction

Shares of Dropbox fell around 2.4% in extended trading on Tuesday following the news.