Once an attacker gets a copy of an encrypted vault, account lockout only ends the live intrusion. The stolen data can still be attacked later on the attacker’s own time, and the service’s normal reset flow does not erase that risk. Dashlane says attackers brute-forced short-lived 2FA codes to register new devices, then used that trust to download encrypted vaults from fewer than 20 personal accounts. The company says there is no evidence its internal systems were compromised, and the vaults still require the customer’s master password to open. That shifts the threat model for password managers and any SaaS product that stores encrypted backups. The break is no longer just account access; it is the possibility that copied vault data can be decrypted later if a master password is weak.
Part of the PlainSec briefing for 2026-06-04