Dashlane said hackers obtained encrypted password vaults belonging to about 20 customer accounts during a cyberattack over the weekend.
According to the password manager company, attackers brute-forced its two-factor authentication system and used that access to register new devices on existing accounts.
The attackers then downloaded copies of certain customers’ encrypted vaults, which contain passwords and other sensitive credentials.
How the attack worked
Dashlane said the goal of the attack was to defeat two-factor authentication, commonly known as 2FA.
The company said attackers used automated tools to rapidly try different combinations until they guessed the correct security code before it expired.
“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” Dashlane said.
The company added that automated software can:
- Submit large numbers of numeric combinations.
- Attempt to guess short-lived security codes.
- Register unauthorized devices once the code is discovered.
Limited number of accounts affected
Dashlane said the attackers gained access to roughly 20 accounts.
The company said there was no evidence that its own systems had been compromised.
It has not explained how the attackers were able to bypass the two-factor protections.
Dashlane said affected customers have been notified.
The company has not said:
- Whether the victims were specifically targeted.
- Who carried out the attack.
- Whether any ransom demand was made.
Company representatives did not respond to requests for comment.
Vaults remain encrypted
The stolen vaults are encrypted and cannot be accessed without the customer’s master password.
Dashlane said those passwords are known only to users and are not stored in plaintext by the company.
However, customers with weak or easily guessed master passwords could face greater risk.
A successful guess could allow attackers to decrypt the stolen vaults and access the information inside.
Steps taken
Dashlane said it has implemented measures aimed at preventing similar incidents.
It did not disclose what changes were made.
Previous breaches highlight risks
Cyberattacks involving password managers are uncommon but can have long-term consequences.
LastPass disclosed in 2022 that hackers had stolen customer password vault backups.
Some older users had weaker password requirements, making it easier for attackers to crack certain vaults. Reports later linked the breach to cryptocurrency theft involving private keys stored inside compromised accounts.
In 2021, Australian software company Click Studios warned users of its Passwordstate password manager to reset credentials after attackers compromised the software’s update mechanism and distributed malware.
TL;DR:
Dashlane said hackers brute-forced two-factor authentication protections and stole encrypted password vaults from about 20 customer accounts. The company said its systems were not breached, but users with weak master passwords could face greater risks.
AI summary:
- Dashlane said attackers stole encrypted vaults from about 20 accounts.
- Hackers bypassed two-factor authentication protections.
- The company said there is no evidence its own systems were compromised.
- Vaults remain encrypted and require users’ master passwords.
- Dashlane has notified affected customers and taken additional security measures.








