Data Breaches
Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
Cyber RTJune 2, 20263 min read

Dashlane reported that fewer than 20 personal plan users had their encrypted vaults downloaded after a brute-force attack aimed at bypassing two-factor authentication. The attack triggered account suspensions due to Dashlane's security controls. Affected users were notified, and the vaults remain secure unless the Master Password is weak. Users are advised to review registered devices, enable 2FA, and use strong passwords.
Dashlane, a popular password manager, recently disclosed a security incident where an unknown threat actor launched a brute-force attack on its platform. This attack specifically targeted users on the personal subscription plan, aiming to bypass two-factor authentication (2FA) and register new devices on existing accounts. The breach resulted in the downloading of encrypted vaults for fewer than 20 users, although the exact number of targeted accounts remains unspecified.
The attack occurred on May 31, 2026, and was characterized by a high volume of login attempts, which triggered Dashlane's security controls. These controls led to temporary account suspensions and authentication issues for the affected users. Despite these security measures, the attackers managed to succeed in a few cases, allowing them to download encrypted data from the vaults of a small number of users.
Dashlane has since restored access to the compromised accounts and has directly notified the affected users. The company reassured its broader user base that if they have not received a specific notification regarding vault risk, their accounts remain secure. This communication aims to alleviate concerns among users who were not directly impacted by the breach.
Importantly, the downloaded vault data remains encrypted and is inaccessible without the Master Password. Dashlane emphasized that unless the Master Password is simple and easily guessable, it is unlikely that the attackers will be able to decrypt the vaults. The company also confirmed that its internal systems were not compromised during the incident, maintaining the integrity of its infrastructure.
In response to the attack, Dashlane has advised all users to take precautionary steps to enhance their account security. This includes reviewing and removing any unrecognized devices registered to their accounts, enabling 2FA, and ensuring their Master Password is strong, unique, and difficult to guess. These measures are intended to bolster user security and prevent future breaches.
The incident highlights the ongoing challenges of cybersecurity, even for companies with robust security protocols. It serves as a reminder of the importance of maintaining strong, unique passwords and utilizing additional security measures like 2FA to protect personal information. Users are encouraged to remain vigilant and proactive in safeguarding their digital assets.
For those interested in staying informed about cybersecurity and related topics, Dashlane recommends following their updates on platforms like Google News, Twitter, and LinkedIn. This incident underscores the importance of staying informed about potential threats and the steps companies are taking to protect user data.


