Hackers breached about 5,000 Dropbox (DBX) accounts last month, accessing files on less than a third of them, Bloomberg reported Tuesday, citing company statement and records.
Some users were told their files were viewed and downloaded during unauthorized access between Aug. 4 and Aug. 21, the report said. The compromised accounts lacked multifactor authentication and were accessed using Lenovo IDs after an issue with Lenovo's email verification process, Dropbox said.
"We recently identified unauthorized access affecting Dropbox accounts connected through Lenovo ID that did not have Dropbox two-factor authentication enabled," Dropbox said in an emailed statement to MT Newswires.
"We expired all sessions authenticated through Lenovo ID, severed any link between Lenovo and a user's Dropbox account, and ensured no one can access Dropbox accounts via Lenovo without first entering their Dropbox password," the company added.
Lenovo said it worked with Dropbox to mitigate the risk and that its customers were not affected.
Dropbox does not expect a material business impact, the report said.
(Market Chatter news is derived from conversations with market professionals globally. This information is believed to be from reliable sources but may include rumor and speculation. Accuracy is not guaranteed.)