Description

Dashlane has revealed that it recently detected and mitigated a targeted brute-force attack aimed at a limited number of user accounts. The incident triggered the company's automated security defenses, which temporarily suspended affected accounts to prevent unauthorized access. While the attack did not compromise Dashlane's infrastructure, a small number of user accounts were successfully targeted, leading to the download of encrypted password vaults. The attackers reportedly attempted repeated authentication requests to gain access to selected accounts and register unauthorized devices. In fewer than 20 cases involving personal-plan subscribers, the threat actors were able to add new devices and obtain encrypted copies of stored vault data. Dashlane stated that the vaults remain protected by users' Master Passwords, meaning the stolen data cannot be readily accessed without successfully decrypting the encrypted contents. The company has notified impacted users and continues to monitor the situation. Organizations and individuals using password managers are advised to maintain strong, unique Master Passwords, enable multi-factor authentication, and regularly review account activity for unauthorized device registrations. Although the number of affected users was limited, the incident highlights the ongoing threat posed by credential-based attacks against online services and the importance of layered account security controls.