Password manager Dashlane suspends customer accounts amid brute-force attacks
Dashlane temporarily suspended some accounts after brute-force login attempts, then restored access the same day. The company said its internal systems were not compromised.
Intelligence analysis by GPT-5.4 Mini

Dashlane says it locked a number of accounts after repeated failed attempts to register new devices, then restored access after investigating. Some users saw 2FA problems and worried the emails were phishing, but the company said there was no internal compromise.
Dashlane is like a big digital key ring that helps people keep their online locks safe. When it saw someone trying lots of wrong keys over and over, it shut some doors for a while to stop trouble.
The company later said the attack did not break into its own systems, and it opened the doors again after checking things. That is a bit like a store locking the front door during a noisy crowd, then reopening once the staff knows everyone is safe.
Some people got worried because the warning emails looked strange and their code app was acting up. The article says the messages were real, but the situation still made customers nervous.
Analysis
What happened
Dashlane said it disabled a number of customer accounts as a precaution during a wave of brute-force attacks. The article says the attacks started on Sunday afternoon, and Dashlane said it had finished investigating later that evening and restored all affected accounts.
The suspension emails told users that their account had been temporarily suspended because someone tried to register a new device and failed to enter the correct token after several attempts. Dashlane also said, in a statement shared with users on social media, that there was no compromise of internal systems.
What users saw
The Register says several users reported login-attempt alerts coming from different countries, with Korea and Russia named as common sources. The story does not say whether any of those attempts succeeded.
Dashlane’s response also affected its two-factor authentication service. Some users said their one-time passcodes returned errors when they tried to use them.
Trust and communication
A separate source of concern was communication. Some users worried the suspension email might be phishing, but the article says the messages had no suspicious links or attachments and came from a real Dashlane domain. Even so, the old logo in the email made some customers uneasy.
By Monday morning, Dashlane’s status page had shifted from “resolved” to “monitoring,” suggesting the company was still watching the situation even after access had been restored. The main open question in the article is the scale of the attack and whether any customer accounts were successfully accessed.
Key points
- Dashlane temporarily suspended some customer accounts after brute-force attacks triggered its protections.
- The company said it restored all affected accounts the same day and found no internal system compromise.
- Some users reported 2FA passcode errors and suspicious login alerts from multiple countries.
- Customers criticized Dashlane for limited public communication about the incident.
- The article says it is unclear whether any customer accounts were successfully accessed.
Dashlane says it restored the affected accounts the same day and found no compromise of internal systems. If that holds, the incident shows its protective controls can react quickly to suspicious login activity.
The episode still exposed how disruptive defensive lockouts can be for customers, especially when 2FA also misfires. If communication stays limited, users may keep mistaking real security notices for phishing and lose confidence in the service.



