By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: Dashlane Temporarily Locks Accounts After Brute Force Attack Targets 2FA Protections
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

Dashlane Temporarily Locks Accounts After Brute Force Attack Targets 2FA Protections

Dashlane automatically locked user accounts after detecting a coordinated brute force attack that attempted to bypass two factor authentication by guessing codes, but fewer than 20 users had encrypted vault data downloaded.

CSBadmin
Last updated: June 2, 2026 11:02 am
CSBadmin
2 Min Read
Share
SHARE

Attack Overview

Dashlane, a popular password manager, experienced a security incident starting May 31, 2026, when an external attacker launched a large scale brute force campaign. The threat actor repeatedly attempted to guess authentication codes designed to protect two factor verification, aiming to register unauthorized devices on user accounts. This high volume of login attempts triggered Dashlane’s automated security systems, which responded by temporarily locking multiple accounts as a precautionary measure to prevent any unauthorized access.

Contents
Attack OverviewImpact and Response

Impact and Response

The attack caused temporary disruptions for some users, including inability to log in or add new devices. Dashlane’s security team immediately launched an investigation and implemented mitigation measures. The company has since restored access to all impacted accounts and confirmed normal operations have resumed. Dashlane emphasized that these account lockouts were part of its defensive strategy and not evidence of successful compromise. However, investigators determined that attackers managed to download encrypted vault data for fewer than 20 users on personal plans, and those individuals have been directly notified. Dashlane reassured users that the stolen vault data remains strongly protected under its zero knowledge encryption model, as vault contents are encrypted using each user’s Master Password, which is never stored or transmitted to company servers. The company confirmed no evidence suggests a breach of its internal infrastructure, as the attack was limited to external authentication attempts. Dashlane has since blocked malicious traffic sources and reinforced its security controls to detect similar patterns in the future.

Source: Cyber Security News

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account LockoutBrute ForceDashlane
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Android Framework Flaw Under Active Attack Allows Remote Privilege Escalation
Next Article IBM Warns of Critical WebSphere Flaw Enabling Remote Code Execution

Trending

StreamRat trojan rides fake TV apps to take over Android devices
September 3, 2026
Signed node.exe is latest cover for malware delivery, Symantec finds
September 3, 2026
Russian man extradited over Excel malware sent to 80,000 freelancers
September 3, 2026
Fake tax and shipping lures push RMM installs across 46 countries
September 3, 2026
Poisoned Git configs make AI coding agents run attacker commands
September 3, 2026

Related Stories

CSBadmin

Deceptive Go Package Hides DNS Backdoor for Years in Supply Chain Attack

CSBadmin

Claude models attacked real companies they mistook for a game

CSBadmin

Apple Enables Encrypted RCS Chat Between iPhone and Android

CSBadmin

Pure Data Theft Extortion Costs US Government Entity $1 Million Payout

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.