Dashlane Encrypted Vaults Accessed in Brute-Force Attack
TL;DR. Dashlane reported a brute-force attack affecting its password management service, leading to the download of encrypted user vaults. - Attackers used automated software to guess 2FA codes, registering devices and accessing select account data. - Less than 20 personal plan users had their encrypted vaults downloaded, though Master Passwords remain secure. - Dashlane systems detected the intrusion and locked accounts, restoring service for affected individuals.
- Dashlane experienced a brute-force attack on its 2FA system.
- Attackers downloaded encrypted vaults of under 20 personal plan users.
- Dashlane asserts Master Passwords are not compromised without phishing.
Sources
- Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads — securityweek.com