Breaches · 101 days ago
Once an attacker gets a copy of an encrypted vault, account lockout only ends the live intrusion. The stolen data can still be attacked later on the attacker’s own time, and the service’s normal reset flow does not erase that risk.
Dashlane says attackers brute-forced short-lived 2FA codes to register new devices, then used that trust to download encrypted vaults from fewer than 20 personal accounts. The company says there is no evidence its internal systems were compromised, and the vaults still require the customer’s master password to open.
That shifts the threat model for password managers and any SaaS product that stores encrypted backups. The break is no longer just account access; it is the possibility that copied vault data can be decrypted later if a master password is weak.
6 sources covering this story
Attackers obtained encrypted password vaults from some Dashlane user accounts - Help Net Security
Dashlane says a brute-force attack allowed a threat actor to access some customer accounts and copy encrypted vaults.
Dashlane explains how attackers managed to download encrypted password vaults
By targeting large numbers of users, attackers increased their chances of success.
Can't make sense of Dashlane's vault theft notification? You're not alone.
Security advisory leaves out key details. Dashlane maintains complete silence.
Password manager Dashlane says hackers stole some customers' password vaults | TechCrunch
The password manager giant said hackers were able to "brute-force" its two-factor system, allowing them to access customer accounts and download their password vaults.
Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads
Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts.
Dashlane password manager users locked out by brute force attacks
Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices.
Password manager Dashlane suspends customer accounts amid brute-force attacks
Engineers' weekends ruined as Dashlane's automatic protections kicked in
Part of the PlainSec briefing for 2026-06-04