Violazioni · 116 giorni fa
Una volta che un attaccante ottiene una copia di un vault crittografato, il blocco dell’account termina solo l’intrusione in tempo reale. I dati rubati possono comunque essere attaccati in un secondo momento, nei tempi dell’attaccante, e il normale flusso di reset del servizio non elimina quel rischio.
6 fonti che coprono questa storia
Attackers obtained encrypted password vaults from some Dashlane user accounts - Help Net Security
Dashlane says a brute-force attack allowed a threat actor to access some customer accounts and copy encrypted vaults.
Dashlane explains how attackers managed to download encrypted password vaults
By targeting large numbers of users, attackers increased their chances of success.
Can't make sense of Dashlane's vault theft notification? You're not alone.
Security advisory leaves out key details. Dashlane maintains complete silence.
Password manager Dashlane says hackers stole some customers' password vaults | TechCrunch
The password manager giant said hackers were able to "brute-force" its two-factor system, allowing them to access customer accounts and download their password vaults.
Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads
Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts.
Dashlane password manager users locked out by brute force attacks
Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices.
Password manager Dashlane suspends customer accounts amid brute-force attacks
Engineers' weekends ruined as Dashlane's automatic protections kicked in
Part of the PlainSec briefing for 2026-06-04