Dashlane Bug Let Hackers Download Encrypted Password Vaults
Key Takeaways Dashlane disclosed a security incident where attackers brute-forced 2FA tokens to register unauthorized devices. This allowed threat actors to download encrypted password vaults...
Key Takeaways
- Dashlane disclosed a security incident where attackers brute-forced 2FA tokens to register unauthorized devices.
- This allowed threat actors to download encrypted password vaults belonging to fewer than 20 personal plan users.
- Dashlane states the stolen vaults remain encrypted and inaccessible without the users’ Master Passwords.
- The company implemented network-level blocks, reactivated accounts, and deployed additional verification layers to device registration flows.
Dashlane Brute-Force Attack Leads to Encrypted Vault Downloads for Some Users
Dashlane, a prominent password management service, has confirmed a security incident involving a targeted brute-force attack against its two-factor authentication (2FA) mechanisms. This sophisticated attack allowed unauthorized devices to be registered to a small number of user accounts, leading to the download of encrypted password vaults. The company emphasizes that fewer than 20 personal plan users were affected, and no compromise of Dashlane’s internal systems occurred.
Table Of Content
Attackers Exploit Device Registration Flow
The incident commenced on Sunday, May 31, 2026, when an external threat actor initiated a large-scale brute-force assault. The attackers specifically targeted Dashlane’s device registration API endpoints, attempting to guess the 6-digit one-time tokens used for 2FA verification. These tokens are typically delivered via email or generated by authenticator applications.
According to Dashlane, their automated security measures effectively responded to the attack, triggering account lockouts for targeted users before the campaign could fully escalate. However, for a limited subset of accounts, the attackers successfully bypassed 2FA by correctly guessing the tokens.
The core of the exploit lay in Dashlane’s device registration process. When a user adds a new device, such as a smartphone or computer, to their account and successfully verifies their identity via 2FA, Dashlane automatically registers the device and downloads a copy of the user’s encrypted password vault to it. By brute-forcing the 2FA tokens, the attackers were able to complete this registration flow, effectively authorizing their own devices and downloading encrypted vault copies without the legitimate account holder’s knowledge or consent.
Limited Impact, Data Remains Encrypted
Dashlane has confirmed that fewer than 20 personal plan users had their encrypted vaults exfiltrated. All affected individuals were directly notified by the company. Despite the successful download of these vaults, Dashlane maintains that the data within them remains inaccessible to the attackers. This assurance stems from the company’s zero-knowledge architecture, where the user’s Master Password is never transmitted to or stored on Dashlane’s servers in plaintext.
The stolen vaults are protected by a robust encryption stack comprising Argon2, AES-256-CBC, and HMAC-SHA256. Dashlane asserts that this combination makes brute-forcing the Master Password statistically infeasible, even with significant computational resources and extended timeframes. The company found no evidence of any compromise to its internal infrastructure during the incident.
Remediation and Enhanced Security
By June 4, 2026, Dashlane announced the conclusion of its investigation, confirming no further customer impact beyond the initial findings. The company implemented several key remediation steps, including:
- Blocking malicious traffic at the network level to prevent further attacks.
- Reactivating all suspended and locked-out user accounts.
- Deploying additional verification layers within the device registration flow to enhance security.
- Hardening API endpoint protections to better detect and filter future malicious traffic.
This incident serves as a critical reminder that even services designed for strong security can be targeted at their authentication perimeters. It underscores the paramount importance of robust 2FA configurations and stringent Master Password hygiene as essential defensive controls for all users.
What You Should Do
- Use a Strong, Unique Master Password: Ensure your Dashlane Master Password is long, complex, and not reused anywhere else.
- Enable and Verify 2FA: Always use two-factor authentication for your Dashlane account and any other critical services. Consider using an authenticator app over SMS for enhanced security.
- Monitor Account Activity: Regularly review your Dashlane account’s security history and device list for any unfamiliar activity or unauthorized devices.
- Stay Informed: Pay attention to security advisories from Dashlane and other service providers to understand potential threats and necessary actions.
- Understand Zero-Knowledge: Trust in the zero-knowledge architecture relies on your Master Password remaining secret. Never share it, and ensure it’s sufficiently strong to resist brute-force attacks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.