Home News Dashlane Confirms Attack Let Hackers Download Encrypted User Vaults After 2FA Bypass Attempt
News

Dashlane Confirms Attack Let Hackers Download Encrypted User Vaults After 2FA Bypass Attempt

Dashlane Investigates Attack That Allowed Hackers to Download Encrypted User Vaults

Password management company Dashlane has completed an investigation into a security incident that resulted in attackers downloading encrypted vault data from a small number of user accounts. The company confirmed that all affected customers have been notified and additional security measures have been deployed.

How the attack happened

The incident began on May 31 when attackers targeted Dashlane users using a brute-force approach against two-factor authentication (2FA) protections. By repeatedly attempting authentication, the attackers were able to register new devices on compromised accounts.

Dashlane explained that its security systems detected the unusual activity and automatically locked many of the targeted accounts. However, before access was fully blocked, the attackers managed to download encrypted vault copies from around 20 personal plan accounts.

What data was accessed

The company clarified that the attackers obtained encrypted vault data only, not decrypted content. Dashlane emphasized that:

  • Vault data cannot be accessed without the Master Password
  • The encryption system uses strong cryptographic standards including Argon2, AES-256-CBC, and HMAC-SHA256
  • Master Passwords are never stored or derived on Dashlane servers due to its zero-knowledge architecture

Dashlane stated there is no evidence that its internal systems were compromised.

How device registration was abused

Normally, when a new device is added, Dashlane verifies the user through a one-time six-digit code sent to the registered email address. Users with 2FA enabled must also provide an authentication app-generated code.

Once verified, the new device is registered and receives a copy of the encrypted vault, which can only be decrypted using the Master Password.

Attackers exploited this flow by successfully bypassing authentication protections through repeated attempts, enabling unauthorized device registration in some cases.

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles

News

DriveSurge Hijacks Thousands of Websites in Massive ClickFix and FakeUpdates Malware Campaign

Hackers Compromise Thousands of Websites in Large-Scale ClickFix and FakeUpdate Malware Campaign...

News

Dragon Weave Cyber Espionage Campaign Uses Cloud-Based Malware to Target Czech Republic and Taiwan

China-Linked Cyber Espionage Campaign “Dragon Weave” Targets Czech Republic and Taiwan A...

News

19-Year-Old Linux Kernel CIFSwitch Vulnerability Enables Root Privilege Escalation Across Major Distributions

19-Year-Old Linux Kernel Flaw Enables Root Privilege Escalation via CIFS Subsystem A...

News

CVE-2026-0257 PAN-OS Vulnerability Actively Exploited Days After Disclosure, Prompting Urgent Global Patching Alerts

Palo Alto Networks PAN-OS Vulnerability Exploited Days After Disclosure, CISA Flags Active...