Dashlane
Coverage of Dashlane in the Nexus archive.
- Dashlane explains how attackers managed to download encrypted password vaults
Dashlane reported that attackers used a brute force attack on its device enrollment API to download encrypted password vaults from fewer than 20 users before automated security systems locked out the accounts. The attack involved generating valid tokens to register new devices on targeted accounts.
- Dashlane issues opaque advisory warning 20 encrypted vaults were stolen
Dashlane issued a security advisory warning that attackers stole 20 encrypted user vaults by launching a brute force attack against two-factor authentication (2FA) protections to register new devices on existing accounts. The advisory states the attack began on May 31, 2026, and a user provided a screenshot of a 2FA request notification received on Sunday.
- Dashlane says hackers stole password vaults via a 'brute force attack'
Hackers used a brute force attack to steal approximately 20 password vaults from Dashlane. The incident highlights a security breach involving unauthorized access to stored password data.
- Password manager Dashlane says hackers stole some customers’ password vaults
Password manager Dashlane reported that hackers used brute-force attacks to breach its two-factor authentication system, allowing access to customer accounts and the theft of password vaults.
- Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
Password manager Dashlane disclosed that fewer than 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack. An external threat actor launched the attack on May 31, 2026, targeting accounts to break two-factor authentication (2FA).
- Dashlane password manager users locked out by brute force attacks
Multiple Dashlane password manager users were locked out of their accounts due to brute-force attacks involving logins from distant locations and unknown devices.
- Password manager Dashlane suspends customer accounts amid brute-force attacks
Password manager Dashlane suspended customer accounts following brute-force attacks, which began on Sunday and led to unauthorized login attempts from Korea and Russia. The company restored accounts after investigating the incident but later changed the status to 'monitoring.' Dashlane confirmed no internal systems were compromised, though users criticized the lack of public communication and faced issues with two-factor authentication.