Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical RCE Flaw in Cursor, VS Code, and Google Antigravity Exposes 50M Developers
August 5, 2026
Critical Microsoft Copilot Vulnerability Lets Attackers Hijack Accounts
August 4, 2026
Microsoft Hardens NuGet Security with Shorter API Key Lifespans
August 4, 2026
Home/CyberSecurity News/Dashlane Bug Let Hackers Download Encrypted Password Vaults
CyberSecurity News

Dashlane Bug Let Hackers Download Encrypted Password Vaults

Key Takeaways Dashlane disclosed a security incident where attackers brute-forced 2FA tokens to register unauthorized devices. This allowed threat actors to download encrypted password vaults...

David kimber
David kimber
June 5, 2026 3 Min Read
52 0

Key Takeaways

  • Dashlane disclosed a security incident where attackers brute-forced 2FA tokens to register unauthorized devices.
  • This allowed threat actors to download encrypted password vaults belonging to fewer than 20 personal plan users.
  • Dashlane states the stolen vaults remain encrypted and inaccessible without the users’ Master Passwords.
  • The company implemented network-level blocks, reactivated accounts, and deployed additional verification layers to device registration flows.

Dashlane Brute-Force Attack Leads to Encrypted Vault Downloads for Some Users

Dashlane, a prominent password management service, has confirmed a security incident involving a targeted brute-force attack against its two-factor authentication (2FA) mechanisms. This sophisticated attack allowed unauthorized devices to be registered to a small number of user accounts, leading to the download of encrypted password vaults. The company emphasizes that fewer than 20 personal plan users were affected, and no compromise of Dashlane’s internal systems occurred.

Table Of Content

  • Key Takeaways
  • Dashlane Brute-Force Attack Leads to Encrypted Vault Downloads for Some Users
  • Attackers Exploit Device Registration Flow
  • Limited Impact, Data Remains Encrypted
  • Remediation and Enhanced Security
  • What You Should Do

Attackers Exploit Device Registration Flow

The incident commenced on Sunday, May 31, 2026, when an external threat actor initiated a large-scale brute-force assault. The attackers specifically targeted Dashlane’s device registration API endpoints, attempting to guess the 6-digit one-time tokens used for 2FA verification. These tokens are typically delivered via email or generated by authenticator applications.

According to Dashlane, their automated security measures effectively responded to the attack, triggering account lockouts for targeted users before the campaign could fully escalate. However, for a limited subset of accounts, the attackers successfully bypassed 2FA by correctly guessing the tokens.

The core of the exploit lay in Dashlane’s device registration process. When a user adds a new device, such as a smartphone or computer, to their account and successfully verifies their identity via 2FA, Dashlane automatically registers the device and downloads a copy of the user’s encrypted password vault to it. By brute-forcing the 2FA tokens, the attackers were able to complete this registration flow, effectively authorizing their own devices and downloading encrypted vault copies without the legitimate account holder’s knowledge or consent.

Limited Impact, Data Remains Encrypted

Dashlane has confirmed that fewer than 20 personal plan users had their encrypted vaults exfiltrated. All affected individuals were directly notified by the company. Despite the successful download of these vaults, Dashlane maintains that the data within them remains inaccessible to the attackers. This assurance stems from the company’s zero-knowledge architecture, where the user’s Master Password is never transmitted to or stored on Dashlane’s servers in plaintext.

The stolen vaults are protected by a robust encryption stack comprising Argon2, AES-256-CBC, and HMAC-SHA256. Dashlane asserts that this combination makes brute-forcing the Master Password statistically infeasible, even with significant computational resources and extended timeframes. The company found no evidence of any compromise to its internal infrastructure during the incident.

Remediation and Enhanced Security

By June 4, 2026, Dashlane announced the conclusion of its investigation, confirming no further customer impact beyond the initial findings. The company implemented several key remediation steps, including:

  • Blocking malicious traffic at the network level to prevent further attacks.
  • Reactivating all suspended and locked-out user accounts.
  • Deploying additional verification layers within the device registration flow to enhance security.
  • Hardening API endpoint protections to better detect and filter future malicious traffic.

This incident serves as a critical reminder that even services designed for strong security can be targeted at their authentication perimeters. It underscores the paramount importance of robust 2FA configurations and stringent Master Password hygiene as essential defensive controls for all users.

What You Should Do

  • Use a Strong, Unique Master Password: Ensure your Dashlane Master Password is long, complex, and not reused anywhere else.
  • Enable and Verify 2FA: Always use two-factor authentication for your Dashlane account and any other critical services. Consider using an authenticator app over SMS for enhanced security.
  • Monitor Account Activity: Regularly review your Dashlane account’s security history and device list for any unfamiliar activity or unauthorized devices.
  • Stay Informed: Pay attention to security advisories from Dashlane and other service providers to understand potential threats and necessary actions.
  • Understand Zero-Knowledge: Trust in the zero-knowledge architecture relies on your Master Password remaining secret. Never share it, and ensure it’s sufficiently strong to resist brute-force attacks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Cisco, Vercel ClawHub Skill Detector Bypassed to Upload Malicious Skills

Next Post

Critical Microsoft Edge Vulnerability Allows Remote Code Execution

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OWASP Releases Subtractive Security Top 10 to Reduce Cyber Risks
August 4, 2026
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us