Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts.

Password manager security

Password management and credential security solutions provider Dashlane revealed on Monday that it has been targeted in a brute-force attack campaign that resulted in a limited number of encrypted vaults being downloaded by the attackers.

According to Dashlane, the attack began on May 31, with attackers attempting to brute-force 2FA to register their own devices on targeted accounts. 

The hackers, the company said, used automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived security code expires”.

Registering a device gives the attacker the access required to download the targeted user’s encrypted vault from Dashlane servers.

The attack was quickly detected and the targeted accounts were automatically locked to limit impact. 

However, Dashlane said the attackers did manage to compromise some accounts. The threat actor downloaded a copy of the encrypted vaults belonging to fewer than 20 personal plan users. 

Advertisement. Scroll to continue reading.

“Dashlane vault data cannot be accessed without the Master Password, and our vault encryption ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time,” Dashlane said

The company noted that the only way for an attacker to obtain a user’s master password is through phishing.

The locked accounts have since been restored and affected users have been notified.

“There is no evidence that Dashlane’s internal system has been impacted,” Dashlane said.

Related: Carnival Data Breach Exposed 6 Million People

Related: Charter Communications Data Breach Could Impact Nearly 5 Million

Related: 185,000 Likely Impacted by 7-Eleven Data Breach

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.