Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs.
Although some affected users did not have Lenovo accounts, the cloud-storage provider said it uses Lenovo Identity Provider Services as part of its authentication infrastructure. This allows users to log into Dropbox accounts using verified Lenovo IDs.
According to the notification sent to impacted users, the unauthorized access was possible due to “an issue with Lenovo’s email verification process,” which “allowed an unauthorized party to register a Lenovo ID using your email address.”
