Attackers registered Lenovo IDs using victims’ email addresses and walked into Dropbox accounts without a password. None had MFA enabled.

Attackers reportedly registered Lenovo IDs using victims’ email addresses, allowing them to sign into existing Dropbox accounts without their passwords.

La violazione sicurezza Dropbox ha coinvolto circa 5000 account, accesso senza password grazie a un difetto di autenticazione Lenovo ID.

Some Dropbox users received an email from the company on Monday notifying them that their accounts have been accessed without authorization between August 4 and August 21,…