Industry
Dashlane explains how attackers managed to download encrypted password vaults
An external party launched a brute force attack on May 31, 2026, targeting Dashlane user accounts by brute-forcing two-factor authentication (2FA) protections to register new devices on existing accou
An external party launched a brute force attack on May 31, 2026, targeting Dashlane user accounts by brute-forcing two-factor authentication (2FA) protections to register new devices on existing accounts. Attackers used automated software to rapidly submit every possible numeric combination for 2FA codes, and when successful, registered a new device to download the user's encrypted vault from Dashlane's servers. Fewer than 20 personal plan users had their encrypted vaults downloaded, though the vaults remain protected by master passwords that Dashlane never stores.
Source: Ars Technica | 2026-06-04