Dashlane – Gaming Master https://gaming.vmondeika.com Get daily gaming updates with us Tue, 02 Jun 2026 19:29:32 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 Hackers brute-forced Dashlane 2FA, downloaded encrypted vaults https://gaming.vmondeika.com/hackers-brute-forced-dashlane-2fa-downloaded-encrypted-vaults/ https://gaming.vmondeika.com/hackers-brute-forced-dashlane-2fa-downloaded-encrypted-vaults/#respond Tue, 02 Jun 2026 19:29:32 +0000 https://gaming.vmondeika.com/hackers-brute-forced-dashlane-2fa-downloaded-encrypted-vaults/ [ad_1]

TL;DR

Attackers brute-forced Dashlane’s 2FA system to register new devices on fewer than 20 accounts, downloading their encrypted password vaults. The vaults remain encrypted with master passwords Dashlane never stores, but users with weak passwords face offline cracking risk.

Dashlane disclosed on Sunday that an external attacker launched a brute-force attack against its two-factor authentication system, successfully bypassing 2FA protections on fewer than 20 personal plan user accounts and downloading copies of their encrypted password vaults. The attack, which began on 31 May, triggered automatic account lockouts across a wider set of targeted users as Dashlane’s security controls detected the high volume of authentication attempts.

The method was straightforward. Attackers used automated software to rapidly submit every possible numeric combination for time-based 2FA codes, attempting to guess the correct sequence before each short-lived code expired. When successful, this allowed them to register a new device on the targeted account, which in turn gave them the access required to download the user’s encrypted vault from Dashlane’s servers.

What was taken and what it means

The encrypted vaults contain the user’s stored passwords, secure notes, and other credentials, but they are encrypted with the user’s master password, which Dashlane says is never sent to its servers in plaintext. The zero-knowledge architecture means that even with a copy of the vault, an attacker cannot access its contents without the master password. Dashlane states that its vault encryption “ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time.”

The 💜 of EU tech

The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!

That assurance holds only if the affected users chose strong, unique master passwords. If any of the fewer than 20 users whose vaults were downloaded used weak or reused master passwords, those vaults could be cracked offline using dictionary attacks or brute-force methods. Credential stuffing attacks, which use passwords exposed in other breaches, are particularly effective against users who reuse credentials across services.

The 2FA weakness

The attack exploited a fundamental limitation of time-based one-time password (TOTP) 2FA codes: they are typically six digits, giving only one million possible combinations per 30-second window. Automated systems can submit thousands of attempts per second, and if rate limiting is insufficiently aggressive, the probability of guessing a valid code within its lifespan becomes non-trivial over many attempts.

Dashlane’s security controls detected the attack and locked affected accounts, which prevented broader compromise but caused disruption for legitimate users who found themselves locked out. The tension between security lockouts and user experience is a recurring challenge for authentication systems: aggressive lockouts stop attackers but also create denial-of-service effects for real users.

Dashlane says its investigation found no evidence that its own systems were compromised. The attack targeted user accounts externally rather than exploiting a vulnerability in Dashlane’s infrastructure.

The LastPass echo

The incident will inevitably draw comparisons to the 2022 LastPass breach, in which attackers stole encrypted password vaults belonging to millions of users. In that case, researchers later confirmed that some vaults with weak master passwords were cracked, leading to cryptocurrency thefts and other real-world harm. Law enforcement has increasingly targeted cybercriminal infrastructure, but offline vault cracking happens beyond the reach of any server-side protection.

The scale is different, fewer than 20 vaults versus millions, but the principle is identical: an encrypted vault is only as secure as the master password protecting it. Dashlane’s advice to affected users is to review registered devices, remove any unrecognised ones, enable 2FA if not already active, and, most critically, use a strong, unique master password that is long and difficult to guess.

The disclosure follows responsible security communication practices, with Dashlane publishing its advisory promptly and providing specific remediation steps. But the incident raises a broader question for the password manager industry: if 2FA can be brute-forced to register new devices, what additional authentication layers are needed to protect the most sensitive consumer security product most people use?

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/hackers-brute-forced-dashlane-2fa-downloaded-encrypted-vaults/feed/ 0
Password manager Dashlane says hackers stole some customers’ password vaults https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/ https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/#respond Tue, 02 Jun 2026 15:45:31 +0000 https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/ [ad_1]

Password manager maker Dashlane says hackers have obtained at least a dozen encrypted vaults used for storing customer passwords during a weekend cyberattack.

The company said on its website that hackers brute-forced the company’s two-factor authentication system, granting the hackers access to about 20 customer accounts. By defeating its two-factor mechanism, the hackers were able to download a copy of certain customers’ encrypted vaults, which store their passwords and other sensitive credentials.

Dashlane said on its incident page that there was no evidence of compromise of its own systems, but it has not yet said how the hackers were able to defeat its two-factor protections in order to access customer accounts. Two-factor is a security feature that protects accounts from being accessed with just a stolen username and password, typically by requiring an additional passcode to be sent to the phone of the account holder.

“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” said Dashlane. The company said that attackers can use automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires.”

The company said it has “taken steps to mitigate the risk of future incidents,” without saying what those were.

Dashlane said it has notified the 20 or so customers whose encrypted vaults were stolen. It’s not yet clear if the specific customers were targeted for a reason, such as because of who they are or what they do for a living.

Spokespeople for Dashlane did not respond to a request for comment. The company has not said if it knows who targeted its customers, or if the hackers contacted Dashlane with demands, such as a ransom.

The stolen vaults are scrambled and cannot be read without the customer’s master password, which is only known by the customer and is not uploaded to Dashlane in plaintext, the company’s website says. But Dashlane said that customers with an easily guessed master password may be at greater risk of having it guessed and their password vaults decrypted.

Data breaches affecting password manager companies are rare, but can have lasting consequences.

In 2022, LastPass confirmed that customer password vault backups were stolen during a cyberattack. While the vaults were protected with passwords only known to the customer, the password requirements for early customers were far weaker than the later standard, allowing hackers to brute-force and easily guess the passwords of some customers’ vaults. There have been several reports of hackers stealing vast amounts of customers’ crypto, likely by using private keys stored in stolen LastPass vaults that had their master passwords cracked following the breach.

A year earlier, Australian software house Click Studios warned all of its customers who use its flagship password manager, Passwordstate, to “reset all credentials” after hackers compromised its software update mechanism to plant malware on customer systems.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

[ad_2]

Source link

]]>
https://gaming.vmondeika.com/password-manager-dashlane-says-hackers-stole-some-customers-password-vaults/feed/ 0