Dashlane password manager users locked out by brute force attacks
Dashlane says brute-force attacks triggered account suspensions for some users, then unsuspended them after investigation.
Intelligence analysis by GPT-5.4 Mini

Dashlane says some users were locked out after automated brute-force attacks from distant locations and unknown devices triggered its security controls. The company says there is no evidence its systems were compromised, but some users still report login trouble.
Dashlane is like a giant key ring that stores lots of people’s passwords. Someone kept trying to guess some users’ keys over and over, like trying every number on a locked bike lock.
Dashlane’s safety system noticed the weird activity and shut the doors on those accounts for a while. That helped block the bad guesses, but it also meant some real users got locked out too.
The company says its own house was not broken into. The problem was more like a guard being extra strict when strangers kept rattling the gate.
Analysis
What happened
Dashlane says some user accounts were targeted in a brute-force attack by an external party. The company told BleepingComputer that its built-in security controls suspended affected accounts to protect them from account hijacking, then later unsuspended them.
Users first reported suspicious access notices on Reddit, including verification emails tied to login attempts from foreign countries and unknown devices. That led some users to worry the messages were phishing, but Dashlane responded in the threads and said its systems were safe and the event was the result of brute-force attempts.
How the response worked
Brute-force attacks try many passwords in succession until one works. Services like Dashlane commonly defend against this with rate limits, CAPTCHA challenges, and account lockouts after repeated failures. In this case, Dashlane’s status page shows an investigation opened on May 31 at 15:19 UTC and was marked resolved by 22:30 UTC the same day, with all affected accounts reportedly unsuspended.
Dashlane later posted another update on June 1 at 07:32 UTC saying it was still monitoring the situation and adding targeted protections. Even so, BleepingComputer says some users continued to report login problems and unresponsive support at the time of publication.
Bottom line
Dashlane says there is no evidence its own systems were compromised. The incident is mainly about attackers trying to take over customer accounts and Dashlane’s defensive controls reacting in a way that temporarily locked out some legitimate users.
Key points
- Dashlane says some accounts were hit by brute-force login attempts from external actors.
- The company suspended affected accounts through its built-in security controls and later unsuspended them.
- Users reported suspicious verification emails and login activity from foreign countries and unknown devices.
- Dashlane says there is no evidence its own systems were compromised.
- Some users still reported login issues and support problems after the status page marked the issue resolved.
Dashlane says the affected accounts were unsuspended and the incident was resolved the same day it was investigated. If the company’s added targeted measures work, similar brute-force attempts may be stopped faster with less disruption. The episode also shows that the service detected suspicious activity quickly enough to react with account protections instead of silently failing.
Even when the provider is not breached, account lockouts can leave legitimate users unable to access critical passwords. If support remains slow or login problems continue, the trust damage can extend beyond the original attack. Repeated brute-force pressure could also force the company to keep tightening defenses in ways that inconvenience users further.



