Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
Dashlane says an external brute-force attack led to encrypted vault downloads for fewer than 20 personal-plan users.
Intelligence analysis by GPT-5.4 Mini

Dashlane says an unknown attacker used brute-force attempts against certain accounts to try to bypass 2FA and add new devices. Fewer than 20 personal users had encrypted vaults downloaded, but Dashlane says the vaults still require the master password to open.
Dashlane says someone kept trying lots of passwords on some accounts, like shaking many doors until one finally opened. That attack was trying to sneak past the extra security step and add a new device.
A few vaults were downloaded, but the vaults are locked with a master password. That is like taking a locked box home without having the key.
Dashlane told the affected users and says its own systems were not hurt. It also told everyone to check which devices are signed in, turn on extra security, and use a password that is hard to guess.
Analysis
What happened
Dashlane says an external threat actor launched a brute-force attack against certain user accounts on May 31, 2026. The apparent goal was to defeat two-factor authentication protections and register new devices on those accounts.
The company says the volume of login attempts triggered its built-in defenses, including temporary account suspensions and authentication problems. Access has since been restored, but Dashlane now says the attackers succeeded in a small number of cases and downloaded encrypted vaults belonging to fewer than 20 personal-plan users.
What the data means
Dashlane says it directly notified the affected users. It also says that if a user did not receive a specific message about vault risk, their account was not impacted.
The important limitation is that the downloaded vaults are encrypted. Dashlane notes that the contents cannot be read without the master password. That means the practical risk depends heavily on whether the master password is strong and hard to guess.
Scope and response
Dashlane says its internal systems were not impacted by the incident. As a precaution, it recommends checking registered devices, removing anything unrecognized, enabling 2FA, and using a long, unique master password.
The incident is narrow in scope, but it still shows how attackers can turn repeated login pressure into a data exposure event even when the core service remains intact.
Key points
- Dashlane says an external brute-force attack targeted certain user accounts.
- The attacker was trying to bypass 2FA and register new devices on accounts.
- Fewer than 20 personal-plan users had encrypted vaults downloaded.
- Dashlane says the vaults still require the master password to read.
- The company says its internal systems were not impacted.
Dashlane says it notified the affected users and restored access after the incident. Its recommendation to review devices, enable 2FA, and use stronger master passwords could reduce the chance of similar account abuse going forward.
Even though the vaults are encrypted, a weak or predictable master password could still put a user's data at risk. The incident also shows that repeated login attacks can bypass account protections for at least some users before defenses stop them.



