Dashlane confirmed that hackers stole roughly 20 password vaults using a brute-force attack.
The company disclosed that attackers brute-forced their way into approximately 20 accounts. The number is small relative to Dashlane's user base, but the method matters more than the count. Brute force means systematically testing passwords until one works, pointing to weak master passwords on the affected accounts, inadequate lockout controls on Dashlane's end, or both.
Password managers are attractive targets precisely because a successful breach delivers not one credential but hundreds. The 2022 LastPass incident showed how durable stolen vaults can be: attackers lifted encrypted vaults and have reportedly been working to crack them offline ever since. Twenty vaults is a reassuring-sounding number; each one still represents a full credential set with no expiration date on the exposure.
Twenty is a small, precise-sounding count. The more pointed question is how many affected accounts Dashlane hasn't identified yet.