Dashlane says hackers stole at least a dozen encrypted password vaults belonging to customers during a cyberattack over the weekend, after attackers managed to break through the company’s two-factor authentication protections.
The password manager company said on its website that the hackers brute-forced its two-factor authentication system and gained access to around 20 customer accounts. After bypassing the 2FA process, the attackers were able to download copies of some customers’ encrypted vaults, which are used to store passwords and other sensitive login details.
Dashlane said there is no evidence that its own internal systems were compromised. However, the company has not yet explained how the attackers were able to defeat its two-factor protections and access customer accounts. Two-factor authentication is designed to protect accounts even if someone has a stolen username and password, usually by requiring an additional code sent to the account owner’s device.
According to Dashlane, the purpose of the attack was to brute-force 2FA protections so the attackers could register new devices on existing user accounts. The company said automated tools can rapidly try every possible numeric code combination in an attempt to guess the correct security code before it expires.
Dashlane said it has taken steps to reduce the risk of similar incidents happening again, but it did not provide details about those measures.
The company has notified the roughly 20 customers whose encrypted vaults were stolen. It is still unclear whether those customers were targeted for a specific reason, such as their identity, profession, or the type of information stored in their accounts.





