Dashlane Warns 20 Encrypted Vaults Stolen in 2FA Attack
TL;DR. Dashlane issued an opaque advisory warning that attackers stole 20 encrypted user vaults after a brute-force attack on two-factor authentication. - Attackers attempted to register new devices by brute-forcing 2FA protections on Dashlane accounts. - Dashlane's advisory lacked clear explanations, leaving users confused about the attack mechanics. - The brute-force method targeted 2FA codes that remained valid for three hours. - The company's security controls automatically locked targeted accounts due to high attempt volumes.
- Dashlane reported 20 encrypted user vaults were compromised following a brute-force attack.
- Attackers targeted two-factor authentication (2FA) to register new devices on existing accounts.
- The 2FA codes remained valid for three hours, potentially aiding brute-force attempts.
- Dashlane's official security advisory provided limited details, causing user confusion.
- Users learned about the incident from third-party sources like Mastodon before direct communication from Dashlane.
Sources
- Dashlane issues opaque advisory warning 20 encrypted vaults were stolen — arstechnica.com