A bug in Lenovo's ID verification system made it possible to access Dropbox accounts, but the bug has since been fixed.
A Lenovo ID flaw let attackers access Dropbox accounts without passwords, with around 5,000 accounts reportedly compromised.
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs.
Multiple Dropbox users have been emailed by the cloud storage company to advise them that a security breach saw ...
Attackers registered Lenovo IDs using victims’ email addresses and walked into Dropbox accounts without a password. None had MFA enabled.
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed.