logo

Attackers obtained encrypted password vaults from some Dashlane user accounts

ID: aafbb6cd-fa42-59e3-b385-444d8e3f2e28

STIX ID: report--aafbb6cd-fa42-59e3-b385-444d8e3f2e28

Feed Name: Help Net Security

Threat Score
45/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Sinisa Markovic

...
...

Dashlane disclosed a brute-force campaign targeting API endpoints used for device registration which generated valid tokens and allowed an attacker to register new devices and download encrypted vaults for fewer than 20 personal-plan customers; the company found no evidence of internal system compromise, deployed additional network and product protections, and warned that stolen encrypted vaults remain susceptible to offline cracking if users have weak master passwords.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.