The attackers exploited a weakness in the file-sharing system. Experts say this exposes the hidden risks of third-party login systems.