Crypto
Home›Crypto›Regulation›Hackers allegedly breach Dropbox accounts via authenti…
Hackers allegedly breach Dropbox accounts via authentication flaw
The reported method involves registering Lenovo IDs with victims’ email addresses, which then enables passwordless access to existing Dropbox accounts.
Decrypt reports that attackers gained access to Dropbox accounts by exploiting an authentication flaw.
According to the report, hackers registered Lenovo IDs using victims’ email addresses, then used those IDs to sign into existing Dropbox accounts.
The accounts could be accessed without passwords, the report says, pointing to a weakness in how authentication was handled.
The breach highlights how account takeover can occur when identity verification depends on email-linked credentials rather than stronger, unique authentication.