Technology · Malaysia Bureau
Dropbox confirms 5,000 accounts breached in security incident
Cloud storage provider Dropbox has disclosed that approximately 5,000 user accounts were compromised during an August security breach. The breach primarily affected accounts linked to Lenovo IDs that lacked two-factor authentication protection.
LSN Malaysia ·

Dropbox revealed that unauthorised access to the accounts occurred through Lenovo ID credentials, affecting users who had not enabled two-factor authentication on their accounts. The company has since taken action to secure the compromised accounts by terminating all active sessions authenticated through Lenovo IDs.
The breach underscores the importance of multi-factor authentication as a critical security measure. Two-factor authentication adds an additional layer of protection by requiring users to verify their identity through a second method beyond their password, making unauthorised account access significantly more difficult.
Users who linked their Dropbox accounts to Lenovo credentials are advised to review their account security settings and consider enabling two-factor authentication to prevent future unauthorised access. Dropbox has not indicated whether any personal data or files stored on the affected accounts were accessed during the breach.
The incident serves as a reminder to Malaysian users and businesses relying on cloud storage solutions to strengthen their security practices, particularly when integrating accounts across multiple platforms. Organisations are increasingly emphasising the adoption of two-factor authentication as standard practice across their digital services.