A brute force attack targeting Dashlane users led to temporary account lockouts and the download of encrypted password vaults belonging to fewer than 20 customers.
Quick Summary – TLDR:
- Dashlane confirmed that attackers targeted user accounts in a brute force campaign on May 31.
- The attack triggered automatic account suspensions and authentication issues for some users.
- Attackers successfully downloaded encrypted vaults belonging to fewer than 20 personal plan users.
- Dashlane says there is no evidence its internal systems were compromised, and affected vaults remain protected by users’ Master Passwords.
What Happened?
Password manager Dashlane has disclosed that a brute force attack against some of its users resulted in temporary account suspensions, login issues, and the download of encrypted vault data belonging to fewer than 20 customers.
The company said the attack was launched by an external threat actor on May 31, with the goal of bypassing two factor authentication protections and registering new devices on existing user accounts.
🚨 A brute-force attack against certain Dashlane accounts bypassed 2FA protections in a handful of cases, allowing attackers to register new devices and download encrypted vault copies.
— The Hacker News (@TheHackersNews) June 2, 2026
Fewer than 20 personal plan users were affected.
Full details: https://t.co/q8YMciCfZd
Attack Triggered Lockouts and Security Alerts
The incident first came to light after multiple Dashlane users reported receiving unexpected security notifications and account suspension emails. Some users also experienced login problems and found themselves locked out of their accounts.
One of the emails sent to affected users stated:
Many users turned to Reddit seeking answers after receiving verification codes and device registration requests from locations they did not recognize. Some initially feared the emails were part of a phishing campaign because Dashlane had not yet publicly explained the situation.
Dashlane later confirmed that the alerts were legitimate and were triggered by an ongoing brute force attack against user accounts.
Email from Dashlane Support
by u/polygenics in Dashlane
How the Attack Worked?
According to Dashlane, the attackers attempted to gain access to accounts by repeatedly trying passwords and authentication codes. The activity generated a high volume of login attempts, which activated the company’s automated security protections.
These safeguards temporarily suspended targeted accounts and created authentication issues for some users. Dashlane said these measures were designed to prevent account takeovers and protect customer data.
The company launched an investigation on May 31 and worked throughout the day to restore affected accounts. By the evening, Dashlane marked the incident as resolved and later stated that suspended accounts had been reinstated.
However, some users continued reporting login difficulties even after the company declared the issue resolved. Dashlane later moved the incident status to monitoring while implementing additional protective measures.
Fewer Than 20 Encrypted Vaults Downloaded
While most targeted accounts remained protected, Dashlane later revealed that attackers successfully registered new devices in a small number of cases.
As a result, copies of encrypted password vaults belonging to fewer than 20 users on the personal subscription plan were downloaded by the attackers.
Dashlane said it directly notified every affected customer.
Importantly, the downloaded data remained encrypted. Accessing the contents of those vaults would require the user’s Master Password, which is not stored by Dashlane.
The company noted that unless a Master Password is weak, simple, or easily guessed, successfully decrypting the vaults would be extremely difficult.
Dashlane Says Internal Systems Remain Secure
Throughout the incident, Dashlane repeatedly emphasized that there was no evidence that its infrastructure had been breached.
Jordan Fylolenko, Dashlane Senior Director of Corporate Communications, said:
The company’s status page also indicated that the incident impacted its email notification and two factor authentication systems during the attack response process.
What Users Should Do Now?
Dashlane is advising users to take several precautionary steps:
- Review all registered devices linked to their account.
- Remove any device they do not recognize.
- Enable two factor authentication if it is not already active.
- Use a strong, unique, and difficult to guess Master Password.
- Monitor account activity for unusual behavior.
These steps can help reduce the risk of unauthorized access and strengthen account security against future attacks.
SQ Magazine Takeaway
I think this incident highlights an important reality about modern cybersecurity. Even when a company has strong security systems in place, attackers continue to target individual user accounts using automated methods. The encouraging part is that Dashlane’s core systems do not appear to have been compromised, and the stolen vaults remained encrypted.
However, the fact that attackers managed to download any vaults at all shows why strong Master Passwords and two factor authentication remain critical for every password manager user.