Dashlane Details How Hackers Managed to Download Encrypted Password Vaults
ID: ff1fd568-e16f-53b2-858c-566be2f7f50d
STIX ID: report--ff1fd568-e16f-53b2-858c-566be2f7f50d
Feed Name: cybersecurityNews.com
**Dashlane brute-force campaign:** Beginning May 31, 2026, attackers conducted a high-volume brute-force attack against Dashlane’s device-registration 2FA endpoints, successfully registering devices and downloading encrypted vaults for fewer than 20 personal-plan users; Dashlane says vaults remain protected by users’ Master Passwords and its zero-knowledge encryption, no internal compromise was found, and mitigations (account lockouts, API hardening, added verification) were applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
