Several Dashlane users were temporarily locked out of their accounts after the password manager detected brute-force login attempts from unfamiliar devices and distant locations.

Dashlane confirmed to BleepingComputer that the account suspensions were triggered by its automated security systems, which are designed to protect users from possible account takeover attempts. The company said the affected accounts were targeted by an external party and were suspended as a precaution while the activity was being handled.

Jordan Fylolenko, Dashlane’s Senior Director of Corporate Communications, said certain user accounts were targeted in a brute-force attack by an outside party, leading to temporary suspensions through Dashlane’s built-in security protections. The company also confirmed that the affected accounts have now been unsuspended.

Dashlane said its team is actively working on the issue and taking additional steps to protect customers. The company also stressed that there is no evidence that Dashlane’s own systems were compromised.

The issue first drew attention after several Dashlane users posted on Reddit saying they had received suspicious access notices from foreign countries. The emails included verification codes that are normally sent when a legitimate account owner tries to register a new device.

Many users were unsure whether the messages were real or part of a phishing campaign aimed at Dashlane customers, especially because they had not attempted to log in from any new device or location.

Dashlane later responded to some Reddit discussions, saying its systems remained secure and that the alerts were caused by brute-force attacks. These attacks involve repeated login attempts using different passwords in an effort to break into an account.

READ
WordPress wp2shell Attacks Begin as Hackers Exploit Critical RCE Flaws Worldwide

Security platforms commonly use protections such as rate limiting, CAPTCHA checks, and temporary account lockouts to stop automated login attacks once too many failed attempts are detected.

According to Dashlane’s status page, the company began investigating the incident on May 31 at 15:19 UTC. By 22:30 UTC, the issue was marked as resolved, with Dashlane saying all affected accounts had been unsuspended.

A further update on June 1 at 07:32 UTC repeated that the incident had been resolved and said Dashlane was continuing to monitor the situation while applying additional targeted protections.

However, some users have continued to report login problems even after Dashlane marked the issue as resolved, with some also saying they have not received a timely response from support.

BleepingComputer asked Dashlane for more details, including how many accounts were affected, but the company had not provided additional information at the time of publication.


Buy ExpressVPN with PayPal or Credit Card

Advertisement