Following a brute-force attempt by an unidentified party, “fewer than” 20 users on the personal membership plan had their encrypted vaults downloaded, according to password manager Dashlane.
According to the firm, a “external” threat actor initiated a brute-force attempt against specific Dashlane user accounts on May 31, 2026, with the intention of circumventing two-factor authentication (2FA) safeguards and enabling the registration of new devices on pre-existing user accounts.
It’s unclear exactly how many people were targeted, but Dashlane claimed that because of its built-in security measures, the huge frequency of attempts on those accounts resulted in temporary account suspensions and login problems.
The company has now disclosed that the attackers were successful in a few instances, allowing them to download a copy of the encrypted vaults belonging to less than 20 personal plan users, even though access to the accounts has since been restored read more about Dashlane Discloses Brute-Force Attack Encrypted Vaults of Fewer Than 20 Users Downloaded.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
