Substrate
technology

Dashlane Says Brute-Force Attack Let Attacker Download Encrypted Password Vaults of Fewer Than 20 Users

Attackers targeted device-registration endpoints on May 31 and obtained copies of fewer than 20 personal-plan vaults. Dashlane says no internal systems were breached and has added verification layers.

forbes.com
Ars Technica
2 sources·Jun 4, 4:02 PM·1m read
Dashlane Says Brute-Force Attack Let Attacker Download Encrypted Password Vaults of Fewer Than 20 Usersforbes.com
Audio version
Tap play to generate a narrated version.
Developing·Limited corroboration so far. This page will refresh as more sources emerge.

Dashlane said attackers used a brute-force campaign on May 31 to target the API endpoints that handle new-device registration. The automated requests generated valid tokens for fewer than 20 personal-plan accounts, allowing the threat actor to register a device on each account and download a copy of the encrypted vault before the attack was stopped.

The company’s automated security systems locked out the targeted accounts as soon as the volume of requests was detected.

Dashlane said the lockouts affected an unknown number of users and that no further impacts have been identified since the investigation concluded. Dashlane stated there is no evidence its internal systems were compromised. The downloaded vaults remained encrypted and cannot be opened without each user’s master password, which the company does not store on its servers.

During normal device registration, Dashlane sends a one-time six-digit code to the user’s registered email or requests a code from an authenticator app when two-factor authentication is enabled. Once the code is entered, the new device receives a copy of the encrypted vault. Dashlane contacted the affected users with instructions on credentials and account security.

The company has added extra verification steps to the device-registration flow and deployed additional network- and product-level filters to block malicious traffic. Dashlane advised all users to enable two-factor authentication. The investigation results were published June 5.

Transparency

How sources framed this
forbes.com
Ars Technica
LeftNeutralRightFailure2FA weakness
CorroborationLimited · 2 sources

Story details

Related Stories

OpenAI Proposes Government Equity Stake via Sovereign Wealth Fundcnbc.com
ai5 hrs ago

OpenAI Proposes Government Equity Stake via Sovereign Wealth Fund

OpenAI and U.S. officials have held talks for more than a year about a potential government stake in the company. The discussions include the possibility of equity donation to seed a public wealth fund.

cnbc.com
Coindesk
2 sources
OpenAI CEO Meets Senator on Public AI Ownership Proposalwinnipegfreepress.com
ai9 hrs ago

OpenAI CEO Meets Senator on Public AI Ownership Proposal

OpenAI CEO Sam Altman met with Sen. Bernie Sanders this week to discuss public equity stakes in AI companies. President Trump separately described a possible partnership giving Americans a stake in AI growth.

Abc News
winnipegfreepress.com
economictimes.indiatimes.com
flipboard.com
4 sources
Reid Hoffman to Leave Microsoft Board at Year-End to Focus on New AI-Biopharma Venturethehindu.com
technology9 hrs ago

Reid Hoffman to Leave Microsoft Board at Year-End to Focus on New AI-Biopharma Venture

LinkedIn co-founder Reid Hoffman, 58, informed the board Tuesday he will not seek reelection. He will remain a director until the company's annual meeting later this year.

cnbc.com
TechCrunch
The New York Times
3 sources