Data Breaches · Credential Theft
Encrypted Vault Copies Outlive the Lockout Once an attacker gets a copy of an encrypted vault, account lockout only ends the live intrusion. The stolen data can still be attacked later on the attacker’s own time, and the service’s normal reset flow does not erase that risk.
Dashlane says attackers brute-forced short-lived 2FA codes to register new devices, then used that trust to download encrypted vaults from fewer than 20 personal accounts. The company says there is no evidence its internal systems were compromised, and the vaults still require the customer’s master password to open.
That shifts the threat model for password managers and any SaaS product that stores encrypted backups. The break is no longer just account access; it is the possibility that copied vault data can be decrypted later if a master password is weak.
6 sources · Jun 5
Timeline Sources Jun 5 Help Net Security
Attackers obtained encrypted password vaults from some Dashlane user accounts - Help Net Security
Dashlane says a brute-force attack allowed a threat actor to access some customer accounts and copy encrypted vaults.
original Jun 5 Ars Technica Security
Dashlane explains how attackers managed to download encrypted password vaults
By targeting large numbers of users, attackers increased their chances of success.
original Jun 3 Ars Technica Security
Can't make sense of Dashlane's vault theft notification? You're not alone.
Security advisory leaves out key details. Dashlane maintains complete silence.
original Part of the PlainSec briefing for 2026-06-03
Every edition of this story: Encrypted Vault Copies Outlive the Lockout
More from today
Data Breaches · Credential Theft
Encrypted Vault Copies Outlive the Lockout Once an attacker gets a copy of an encrypted vault, account lockout only ends the live intrusion. The stolen data can still be attacked later on the attacker’s own time, and the service’s normal reset flow does not erase that risk.
Dashlane says attackers brute-forced short-lived 2FA codes to register new devices, then used that trust to download encrypted vaults from fewer than 20 personal accounts. The company says there is no evidence its internal systems were compromised, and the vaults still require the customer’s master password to open.
That shifts the threat model for password managers and any SaaS product that stores encrypted backups. The break is no longer just account access; it is the possibility that copied vault data can be decrypted later if a master password is weak.
6 sources · Jun 5
Timeline Sources Jun 5 Help Net Security
Attackers obtained encrypted password vaults from some Dashlane user accounts - Help Net Security
Dashlane says a brute-force attack allowed a threat actor to access some customer accounts and copy encrypted vaults.
original Jun 5 Ars Technica Security
Dashlane explains how attackers managed to download encrypted password vaults
By targeting large numbers of users, attackers increased their chances of success.
original Jun 3 Ars Technica Security
Can't make sense of Dashlane's vault theft notification? You're not alone.
Security advisory leaves out key details. Dashlane maintains complete silence.
original Part of the PlainSec briefing for 2026-06-03
Every edition of this story: Encrypted Vault Copies Outlive the Lockout
More from today