Security/ password-managers · 2fa · brute-force · data-breach

Dashlane's 2FA Was Brute-Forced, Encrypted Vaults Downloaded

An attacker bypassed two-factor authentication on fewer than 20 Dashlane accounts and walked off with copies of their encrypted password vaults.

An attacker brute-forced Dashlane's two-factor authentication system and downloaded encrypted password vaults from fewer than 20 accounts.

Dashlane disclosed the incident on Sunday, two days after the attack began on May 31. The attacker bypassed 2FA protections on fewer than 20 personal plan accounts, downloading encrypted copies of those users' vaults. A wider set of targeted accounts was locked out automatically before the attacker got to them. Dashlane has not said what weakness in its 2FA implementation let the brute-force attempt succeed in the first place.

When a password manager gets hit, the stakes are different. Users hand these services credentials to everything else, which makes a successful 2FA bypass particularly pointed. It suggests rate-limiting or lockout thresholds failed before any vault was touched. The encrypted vaults limit the immediate damage, but that protection only holds as long as master passwords stay secret.

LastPass users heard something similar in 2022: encrypted vaults were stolen, but the encryption kept things manageable. That framing wasn't entirely wrong. It wasn't entirely comfortable either, and Dashlane is now in the same position.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →