Dashlane explains how attackers managed to download encrypted password vaults
Dashlane said that attackers mounted a coordinated hacking campaign against a large base of its users in an attempt to recover as many encrypted password vaults as possible. The password manager provider said fewer than 20 personal user vaults were downloaded before it shut down the operation. In a campaign that started Sunday, the unknown threat actor abused the mechanism that allows Dashlane users to add new devices, such as computers or phones, to their accounts. By abusing Dashlane's programming interfaces for device enrollment, the attackers sent requests to large numbers of existing users’ registered email addresses. In an update published Thursday, Dashlane wrote: The threat actor targeted the API endpoints for device registration and used a brute force attack to send a large volume of automated requests to those endpoints. In response, Dashlane’s automated security systems operated as intended, triggering an automatic lockout of the targeted accounts to protect those users. Before the attack was fully mitigated, the threat actor was able to brute force and generate valid tokens for fewer than 20 personal plan customers, allowing them to register a new device on those accounts and download copies of users’ encrypted vaults. The flow and strategy of the attack When a user installs the Dashlane app on a new device and attempts to enroll it in their existing account, Dashlane first verifies the account holder's identity. This verification is completed by sending a one-time six-digit token to the user’s registered email address (or, for users who have enabled two-factor authentication, by validating a six-digit code generated by their authentication app). Read full article Comments
k6-user-615341 • 2026-06-05 17:09
k6-load-test-comment-54019882
k6-user-615341 • 2026-06-05 17:09
k6-load-test-comment-54019882
k6-user-615341 • 2026-06-05 17:09
k6-load-test-comment-54019882
k6-user-615341 • 2026-06-05 17:09
k6-load-test-comment-54019882
k6-user-615341 • 2026-06-05 17:09
k6-load-test-comment-54019882
k6-user-615341 • 2026-06-05 17:09
k6-load-test-comment-54019882
k6-user-615341 • 2026-06-05 17:09
k6-load-test-comment-54019882
k6-user-948085 • 2026-06-05 17:01
k6-load-test-comment-76383538
k6-user-948085 • 2026-06-05 17:01
k6-load-test-comment-76383538
k6-user-948085 • 2026-06-05 17:01
k6-load-test-comment-76383538
k6-user-948085 • 2026-06-05 17:01
k6-load-test-comment-76383538
k6-user-359784 • 2026-06-05 20:42
k6-load-test-comment-761482422
k6-user-575341 • 2026-06-05 20:42
k6-load-test-comment-252657530
k6-user-514611 • 2026-06-05 20:42
k6-load-test-comment-232744521
k6-user-979688 • 2026-06-05 20:42
k6-load-test-comment-680870477
k6-user-979688 • 2026-06-05 20:42
k6-load-test-comment-680870477
k6-user-272101 • 2026-06-05 20:42
k6-load-test-comment-358300063
k6-user-243003 • 2026-06-06 20:26
k6-load-test-comment-807307029
k6-user-971764 • 2026-06-06 20:26
k6-load-test-comment-721565604
k6-user-194240 • 2026-06-06 20:26
k6-load-test-comment-633738765
k6-user-103836 • 2026-06-06 20:26
k6-load-test-comment-556543376
k6-user-290013 • 2026-06-06 20:26
k6-load-test-comment-709161257
k6-user-103836 • 2026-06-06 20:26
k6-load-test-comment-556543376
k6-user-194240 • 2026-06-06 20:26
k6-load-test-comment-633738765
k6-user-243003 • 2026-06-06 20:26
k6-load-test-comment-807307029
k6-user-550308 • 2026-06-06 20:26
k6-load-test-comment-295847242
k6-user-260592 • 2026-06-06 20:26
k6-load-test-comment-912453460
k6-user-756787 • 2026-06-06 20:26
k6-load-test-comment-895045985
k6-user-194240 • 2026-06-06 20:26
k6-load-test-comment-633738765
k6-user-331059 • 2026-06-06 20:26
k6-load-test-comment-196207291
k6-user-756787 • 2026-06-06 20:26
k6-load-test-comment-895045985
k6-user-331059 • 2026-06-06 20:26
k6-load-test-comment-196207291
k6-user-970548 • 2026-06-06 20:26
k6-load-test-comment-418470696
k6-user-550308 • 2026-06-06 20:26
k6-load-test-comment-295847242
k6-user-758659 • 2026-06-06 20:26
k6-load-test-comment-508455914
k6-user-756787 • 2026-06-06 20:26
k6-load-test-comment-895045985