Dashlane Accounts Locked After Brute-Force Attacks
Key Takeaways Dashlane experienced a large-scale brute-force attack starting May 31, 2026, aimed at user accounts. Attackers attempted to bypass two-factor authentication by guessing codes to...
Key Takeaways
- Dashlane experienced a large-scale brute-force attack starting May 31, 2026, aimed at user accounts.
- Attackers attempted to bypass two-factor authentication by guessing codes to register unauthorized devices.
- Dashlane’s automated defenses successfully locked numerous accounts, preventing widespread unauthorized access.
- Fewer than 20 users on personal plans had encrypted vault data downloaded, but Dashlane assures this data remains secure due to zero-knowledge encryption.
- No breach of Dashlane’s internal infrastructure occurred; the attack was limited to external authentication attempts.
Dashlane Confronts Brute-Force Attack Targeting User Accounts
Password management giant Dashlane has revealed a significant security incident involving a large-scale brute-force attack that began on May 31, 2026. The sophisticated campaign sought to compromise user accounts by repeatedly attempting to guess two-factor authentication (2FA) codes, aiming to register unauthorized devices.
Table Of Content
Dashlane’s internal security systems quickly identified the malicious activity. This triggered automated defensive measures, which included temporarily locking numerous user accounts as a proactive step to block unauthorized access and prevent attackers from achieving their objectives.
Incident Response and Account Status
Following detection, Dashlane’s security teams immediately launched an investigation and implemented mitigation strategies to contain the attack. While the incident led to temporary disruptions, such as users being unable to log in or add new devices, Dashlane has since confirmed that all affected accounts have had full access restored and normal operations have resumed. The company emphasized that these account lockouts were a direct result of its protective mechanisms, not an indication of successful account compromise.
Further investigation showed that, for fewer than 20 users on personal plans, attackers managed to download encrypted vault data. Dashlane has directly informed all individuals affected by this specific data exposure. The company explicitly stated that users who did not receive a direct notification were not impacted by this particular aspect of the incident.
Dashlane reiterated that the integrity of the downloaded vault data remains robustly protected by its zero-knowledge encryption model. This architecture ensures that vault contents are encrypted using a user’s unique Master Password, which is never stored on or transmitted to Dashlane’s servers. Consequently, without knowledge of the Master Password, decrypting the vault is considered computationally infeasible, even with extensive brute-force efforts.
The company also confirmed that there is no evidence indicating a breach of its internal infrastructure. The attack was confined to external authentication attempts and did not involve the exploitation of backend systems or vulnerabilities within Dashlane’s core platform.
Mitigation and Ongoing Vigilance
In response to the incident, Dashlane has taken decisive action, blocking identified malicious traffic sources and reinforcing its existing security controls. Additional safeguards have been deployed to enhance detection capabilities and mitigate similar attack patterns in the future. The company reiterated its commitment to continuously strengthening its resilience against evolving threats while prioritizing user privacy and account protection.
Dashlane’s investigation is ongoing, with promises of further updates should new findings emerge. An initial advisory was also clarified to ensure precise communication regarding the nature of the attack.
This incident serves as a critical reminder of the increasing sophistication of brute-force campaigns targeting password managers. It underscores the paramount importance of robust authentication practices, including the use of strong, unique master passwords and diligent monitoring of account activity.
What You Should Do
- Enable and Verify 2FA: Ensure two-factor authentication is active on your Dashlane account and any other critical online services. Regularly review your 2FA settings and registered devices.
- Strengthen Your Master Password: If you haven’t already, create an extremely strong, unique Master Password for Dashlane that combines uppercase and lowercase letters, numbers, and symbols, and is at least 12-16 characters long. Do not reuse this password anywhere else.
- Monitor Account Activity: Regularly check your Dashlane account for any unusual login attempts or activity. Report suspicious behavior immediately.
- Beware of Phishing: Remain vigilant against phishing attempts that might try to trick you into revealing your Master Password or 2FA codes. Always verify the sender and the legitimacy of links before clicking.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.