Dashlane Says Hackers Used Brute-Force Attacks To Download Encrypted Vaults Via 2FA
Image: The Hacker News

Dashlane Says Hackers Used Brute-Force Attacks To Download Encrypted Vaults Via 2FA

02 June, 2026.Technology and Science.12 sources

The story in 15 seconds

  • Coordinated brute-force attack targeted Dashlane's 2FA to access vaults.
  • Fewer than 20 user vaults were downloaded before shutdown.
  • Internal infrastructure not breached; traffic from attackers was blocked.

The divide · 1 of 3

How the incident is characterized (2FA bypass vs broader architectural criticism)

One frames a specific brute-force 2FA bypass; others generalize to structural weaknesses.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
12 sources
Western Mainstream
5
Other
5
Local Western
2

Local Western

01net
01net

These 3 password managers are not as secure as expected; 25 vulnerabilities have been discovered

04 June, 2026

Read the original →
Engadget
Engadget

Dashlane Says Hackers Stole Password Vaults Via A 'Brute Force Attack'

02 June, 2026

Read the original →

Western Mainstream

Ars Technica
Ars Technica

Can’t make sense of Dashlane’s vault theft notification? You’re not alone.

03 June, 2026

Read the original →
Ars Technica
Ars Technica

Dashlane explains how attackers managed to download encrypted password vaults

04 June, 2026

Read the original →
Le Temps
Le Temps

Even password managers, though so useful, have security flaws... Here's how to protect your online accounts.

04 June, 2026

Read the original →
TechCrunch
TechCrunch

Password manager Dashlane says hackers stole some customers’ password vaults

02 June, 2026

Read the original →
The Hacker News
The Hacker News

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

02 June, 2026

Read the original →

Other

Gadgets 360
Gadgets 360

Dashlane Password Manager Reveals Hackers Stole Some Encrypted Vaults Using Brute-Force Attacks

04 June, 2026

Read the original →
Journal du Geek
Journal du Geek

Meilleur gestionnaire de mots de passe : lequel choisir en 2026 ?

04 June, 2026

Read the original →
SecurityWeek
SecurityWeek

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

02 June, 2026

Read the original →
SQ Magazine
SQ Magazine

Dashlane Confirms Brute Force Attack on User Accounts

02 June, 2026

Read the original →
Tech Times
Tech Times

Dashlane Password Vault Attack Exposes Security Risks in Two-Factor Authentication Systems

03 June, 2026

Read the original →

Full story

Dashlane 2FA brute-force

Dashlane said attackers mounted a coordinated hacking campaign against a large base of its users to recover encrypted password vaults by targeting its two-factor authentication (2FA) system.

A team of researchers from ETH Zurich and the Università della Svizzera Italiana in Switzerland has discovered vulnerabilities in several password managers, namely Bitwarden, Dashlane, and LastPass

01net01net

In Dashlane’s account, the threat actor used brute force to send a large volume of automated requests to API endpoints for device registration, and Dashlane said its automated security systems triggered an automatic lockout of targeted accounts.

Image from 01net
01net01net

Dashlane also said fewer than 20 personal user vaults were downloaded before it shut down the operation, and that vault contents remain unreadable until a user enters the master password.

Ars Technica described Dashlane’s device enrollment flow as requiring a one-time six-digit token sent to a user’s registered email address, or a six-digit code from an authentication app when 2FA is enabled, before Dashlane approves enrollment and sends a copy of the encrypted vault to the device.

Encryption claims and limits

Dashlane confirmed that approximately 20 encrypted user vaults were downloaded during the attack, while the company stressed that stolen data remains secure due to strong encryption protections.

Tech Times added that accessing vault contents requires a Master Password, which is not stored by Dashlane and is essential for decrypting stored credentials, and that without it the exposed data is considered unreadable.

Image from Ars Technica
Ars TechnicaArs Technica

Gadgets 360 reported that Dashlane said its “external party” launched a “brute force attack” against “certain” user accounts on May 31, and that the company said its vault encryption ensures attempts are “statistically unlikely to succeed.”

Le Temps cited EPFL researchers who analyzed the security architecture of Bitwarden, LastPass, and Dashlane, and the article quoted Matilda Backendal saying, "we have demonstrated that this is not the case".

Broader password-manager risk

Beyond Dashlane’s incident, 01net reported that researchers from ETH Zurich and the Università della Svizzera Italiana discovered vulnerabilities in Bitwarden, Dashlane, and LastPass, and said the “zero-knowledge encryption” model does not always live up to its promises.

Dashlane said that attackers mounted a coordinated hacking campaign against a large base of its users in an attempt to recover as many encrypted password vaults as possible

Ars TechnicaArs Technica

01net said the researchers designed 25 different cyberattacks and that a compromised server could access encrypted data under precise conditions, including through features like account recovery and vault sharing.

The article also described a Dashlane-specific issue tied to compatibility with older versions, saying a hacker who controls a server can force the app to switch to an older, weaker system and then “send thousands of decryption attempts to the server,” with the operation taking about 125 days.

In response to the broader critique, 01net quoted lead researcher Matteo Scarlata telling Ars Technica that the 'zero knowledge' term seems to mean different things to different companies, and that the term no longer has much to do with the mathematical concept of a zero-knowledge proof.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Technology and Science