Skip to main content Skip to search Skip to main navigation
Menu
Important Cybersecurity Score: 8/10

Dashlane: Brute-Force Attack Copies Nearly 20 Password Vaults

Criminals attempted to bypass Dashlane accounts' 2FA via brute force. Nearly 20 vaults were copied – encrypted and, according to the provider, inaccessible.

What happened?

Password manager provider Dashlane has reported a security incident: criminals carried out brute-force attacks against certain user accounts. According to the company, they managed to copy fewer than 20 password vaults belonging to users with a "Personal" subscription. Business accounts were reportedly not affected. Dashlane support assures that the data is encrypted and inaccessible without the master password.

The details

According to a support post from Dashlane, the attacks began on Sunday, May 31, 2026, targeting certain unspecified accounts. The attackers' goal was to bypass two-factor authentication via brute force in order to register new devices to existing user accounts.

The device registration mechanism requires a six-digit 2FA code, which is either generated via an authenticator app or sent by email. If the code is correct, the new device can download the password vault. It was precisely this process that the attackers attempted to crack through mass requests.

However, the sheer volume of requests triggered Dashlane's automated security systems, which subsequently locked the affected accounts. The Dashlane team received a corresponding alert and investigated the incident. As a result, numerous users experienced temporarily locked accounts – access has since been restored, according to the provider.

The investigation was concluded toward the end of last week. Dashlane states that affected users have already been notified directly. Anyone who did not receive a notification is reportedly not affected. The investigation found no further impact on Dashlane's systems.

Analysis

Even if attackers successfully bypassed the device registration mechanism and downloaded a vault, it remains inaccessible without the master password, according to Dashlane. The company states it uses a combination of Argon2, AES-256-CBC, and HMAC-SHA256 encryption. This combination of modern methods is intended to ensure that attempts to access the encrypted contents are statistically unlikely to succeed – even over extended periods of time.

A look at previous incidents in the industry shows just how essential robust encryption of password vaults truly is: back in late 2022, password manager service LastPass admitted that unauthorized parties had breached its cloud systems and gained access to customer data. At the time, password vaults copied from backups contained unencrypted URLs as well as encrypted usernames and passwords. About a year later, the attackers apparently managed to crack the vaults, emptying the cryptocurrency wallets of affected users.

The current Dashlane incident once again demonstrates that centrally stored password vaults remain an attractive target for attackers – and that the quality of the encryption used determines just how serious a successful breach of the cloud infrastructure actually turns out to be.

Practical tips

  • According to the provider, users who have not received a direct notification from Dashlane are not affected by the incident.
  • A strong, unique master password remains the central protective barrier, as vaults are reportedly inaccessible without it, according to Dashlane.
  • Using an authenticator app instead of email-based 2FA codes can generally reduce the attack surface for brute-force attempts targeting device registrations.
  • Affected users and all users in general should closely monitor official statements from the provider to stay informed of the current situation.

Outlook

Dashlane states that the investigation into the incident has been completed and that no further impact on its own systems was identified. The affected accounts have been unlocked again. However, as the LastPass case shows, it can sometimes take considerable time before it becomes clear whether copied, encrypted data can later be decrypted after all. Users and the security community will therefore need to keep an eye on whether the Dashlane incident leads to further consequences in the long run.