๐Ÿ“… Friday, 4 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Celah Lenovo ID Bikin 5.000 Akun Dropbox Terbuka 18 Hari - Tak Butuh Password atau Kotak Masuk

Lenovo ID Flaw Leaves 5,000 Dropbox Accounts Exposed for 18 Days - No Password or Inbox Access Needed

Approximately 5,000 Dropbox accounts were accessed without authorization between August 4 and August 21, 2026. Attackers breached the accounts not by guessing passwords, but by exploiting a vulnerability in Lenovo ID’s third-party authentication system.

The root of the incident stems from Lenovo’s system failing to verify email addresses during new account registrations. Attackers exploited this security loophole by creating new Lenovo ID accounts using victims’ email addresses. Once registered, the attackers simply used the quick login or Single Sign-On (SSO) option to access the Dropbox storage. This tactic allowed hackers to bypass Dropbox passwords entirely, without even needing access to the victims’ email inboxes to confirm registration.

Yoni Levy, a developer, shared the anomaly that hit his account. He noted that he had never signed up for Lenovo services and had never traveled to the UK. However, his security logs recorded a login activity originating from “Near Canary Wharf, England” on August 18 at 6:06 AM.

Criteria for Accounts Affected by the Flaw

Dropbox management has issued official notifications to the thousands of targeted users. Out of the 5,000 compromised accounts, the company noted that fewer than a third of the victims had their personal files viewed or downloaded by the perpetrators. Dropbox detailed that the Lenovo ID SSO exploit only succeeded on accounts meeting two conditions: being linked to Lenovo ID and lacking two-factor authentication (2FA) enabled in their settings.

Why Target Integrated Accounts?

On the same day the Dropbox incident surfaced, a wave of unsolicited password reset emails also hit users of platform X. X quickly responded, confirming there was no evidence of a breach within their internal systems. According to an X engineer’s suspicion, the barrage of forced login attempts was orchestrated by attackers aiming to hijack accounts to access the X Money financial service.

X Money’s operational expansion recently rolled out to Premium and Premium+ subscribers across the United States. Its latest offerings include yield instruments of up to 6% and a 3% card cashback feature. Those high yields make it a prime target for hackers seeking loopholes to steal digital assets.

The consecutive incidents at Dropbox and X demonstrate how lax third-party verification can grant cross-platform access. For users of financial services, enabling two-factor authentication is an absolute necessity before an unknown party alters your access in the early hours. Reported by Decrypt.

Read also: This US Girl Drained $5 Million Posing as Crypto Support - Instead of Hiding, She Called Victims to Mock Them


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share