discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Dashlane password manager users locked out by brute force attacks

Dashlane says brute-force attacks triggered account suspensions for some users, then unsuspended them after investigation.

By Bill Toulas·Jun 1·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Dashlane password manager users locked out by brute force attacks
Image: bleepingcomputer.com

Dashlane says some users were locked out after automated brute-force attacks from distant locations and unknown devices triggered its security controls. The company says there is no evidence its systems were compromised, but some users still report login trouble.

Why it matters

Password managers are a high-value target because they sit in front of many other accounts. This incident shows how brute-force activity can create real user disruption even when the provider’s defenses appear to have worked.

Dashlane is like a giant key ring that stores lots of people’s passwords. Someone kept trying to guess some users’ keys over and over, like trying every number on a locked bike lock.

Dashlane’s safety system noticed the weird activity and shut the doors on those accounts for a while. That helped block the bad guesses, but it also meant some real users got locked out too.

The company says its own house was not broken into. The problem was more like a guard being extra strict when strangers kept rattling the gate.

Analysis

What happened

Dashlane says some user accounts were targeted in a brute-force attack by an external party. The company told BleepingComputer that its built-in security controls suspended affected accounts to protect them from account hijacking, then later unsuspended them.

Users first reported suspicious access notices on Reddit, including verification emails tied to login attempts from foreign countries and unknown devices. That led some users to worry the messages were phishing, but Dashlane responded in the threads and said its systems were safe and the event was the result of brute-force attempts.

How the response worked

Brute-force attacks try many passwords in succession until one works. Services like Dashlane commonly defend against this with rate limits, CAPTCHA challenges, and account lockouts after repeated failures. In this case, Dashlane’s status page shows an investigation opened on May 31 at 15:19 UTC and was marked resolved by 22:30 UTC the same day, with all affected accounts reportedly unsuspended.

Dashlane later posted another update on June 1 at 07:32 UTC saying it was still monitoring the situation and adding targeted protections. Even so, BleepingComputer says some users continued to report login problems and unresponsive support at the time of publication.

Bottom line

Dashlane says there is no evidence its own systems were compromised. The incident is mainly about attackers trying to take over customer accounts and Dashlane’s defensive controls reacting in a way that temporarily locked out some legitimate users.

Key points

  • Dashlane says some accounts were hit by brute-force login attempts from external actors.
  • The company suspended affected accounts through its built-in security controls and later unsuspended them.
  • Users reported suspicious verification emails and login activity from foreign countries and unknown devices.
  • Dashlane says there is no evidence its own systems were compromised.
  • Some users still reported login issues and support problems after the status page marked the issue resolved.
The Upside

Dashlane says the affected accounts were unsuspended and the incident was resolved the same day it was investigated. If the company’s added targeted measures work, similar brute-force attempts may be stopped faster with less disruption. The episode also shows that the service detected suspicious activity quickly enough to react with account protections instead of silently failing.

The Downside

Even when the provider is not breached, account lockouts can leave legitimate users unable to access critical passwords. If support remains slow or login problems continue, the trust damage can extend beyond the original attack. Repeated brute-force pressure could also force the company to keep tightening defenses in ways that inconvenience users further.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritypassword-managementauthenticationaccount-lockoutinfosec

Author

Bill Toulas

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 1, 2026

Source

bleepingcomputer.com

Share

Topics

securitypassword-managementauthenticationaccount-lockoutinfosec

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…