Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads
Dashlane brute-force attack compromised encrypted vaults of fewer than 20 users via 2FA bypass.
Summary
Dashlane reported a brute-force attack campaign beginning May 31 that targeted 2FA codes to register unauthorized devices and download encrypted user vaults. Attackers used automated software to guess numeric 2FA combinations; fewer than 20 personal plan users were compromised. Dashlane's encryption rendered the downloaded vaults inaccessible without master passwords, and affected accounts were locked and restored.
Full text
Password management and credential security solutions provider Dashlane revealed on Monday that it has been targeted in a brute-force attack campaign that resulted in a limited number of encrypted vaults being downloaded by the attackers. According to Dashlane, the attack began on May 31, with attackers attempting to brute-force 2FA to register their own devices on targeted accounts. The hackers, the company said, used automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived security code expires”. Registering a device gives the attacker the access required to download the targeted user’s encrypted vault from Dashlane servers. The attack was quickly detected and the targeted accounts were automatically locked to limit impact. However, Dashlane said the attackers did manage to compromise some accounts. The threat actor downloaded a copy of the encrypted vaults belonging to fewer than 20 personal plan users. Advertisement. Scroll to continue reading. “Dashlane vault data cannot be accessed without the Master Password, and our vault encryption ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time,” Dashlane said. The company noted that the only way for an attacker to obtain a user’s master password is through phishing. The locked accounts have since been restored and affected users have been notified. “There is no evidence that Dashlane’s internal system has been impacted,” Dashlane said. Related: Carnival Data Breach Exposed 6 Million People Related: Charter Communications Data Breach Could Impact Nearly 5 Million Related: 185,000 Likely Impacted by 7-Eleven Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance RateRomanian Hacker Sentenced to Prison in US for Selling Access to State NetworkLA Metro Cyberattack Linked to Iranian State-Sponsored HackersAnthropic Releases New Claude Sandbox, Security Guidance PluginAnthropic Expands Claude’s Enterprise Security Governance With 28 New IntegrationsGhost CMS Vulnerability Exploited to Hack Over 700 WebsitesOncology Institute Discloses Data BreachAnthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects Latest News Supply Chain Attack Hits 32 Red Hat NPM PackagesOracle’s First Monthly Patches Resolve 77 VulnerabilitiesWP Maps Pro Vulnerability Exploited to Take Over WordPress SitesDutch Police Dismantle Massive 17-Million-Device BotnetCritical Windows Netlogon Vulnerability in Attackers’ CrosshairsDragos Acquires xIoT Security Firm PhosphorusAs the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit On-Demand Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the MoveRapid7 announced that Wael Mohamed will assume the role of Chief Executive Officer, replacing current Chief Executive Officer Corey Thomas, who will become Executive Chairman of the Board.Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter.CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.More People On The MoveExpert Insights Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — Brute-force attack / automated 2FA bypass tool