Cybersecurity firm Dashlane has confirmed that hackers successfully bypassed its two-factor authentication (2FA) system during a weekend cyberattack to steal the encrypted password vaults of approximately 20 customer accounts.
The company disclosed on its website that attackers used brute-force methods against its 2FA mechanism. By defeating this security layer, the intruders gained unauthorised entry to the affected accounts and downloaded copies of their encrypted vaults, which contain highly sensitive credentials and passwords.
How the 2FA Security Defences Were Breached
According to Dashlane’s incident page, there is no evidence that its core systems were compromised. However, the company has yet to clarify how the attackers managed to circumvent the 2FA protections. Typically, 2FA serves as a vital security shield, preventing unauthorised access by requiring a temporary code sent to the account owner’s mobile device in addition to their standard login credentials.
“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” Dashlane explained. The password manager provider noted that the perpetrators utilised automated software to rapidly submit every possible numeric combination, attempting to guess the active sequence before the short-lived security code expired.
While Dashlane stated that it has “taken steps to mitigate the risk of future incidents”, it declined to provide specific details regarding what those security measures entail.
Are Affected Customers’ Vaults at Risk?
Dashlane has directly notified the 20 affected users whose encrypted databases were stolen. At this stage, it remains unclear whether these specific individuals were targeted intentionally due to their professions, high-profile status, or other specific reasons.
Spokespeople for Dashlane did not return requests for comment. Additionally, the firm has not revealed whether it knows the identity of the threat actors or if any ransom demands have been made.
Crucially, the stolen vaults remain heavily scrambled. They cannot be decrypted without each user’s unique master password. Dashlane stresses on its support site that it does not store these master passwords in plaintext. However, the company warned that customers who use weak, easily guessed master passwords face a significantly higher risk of having their vaults cracked by the attackers.
A Worrying Trend for Password Managers
Though data breaches involving major password management platforms are relatively rare, their potential fallout can be severe and long-lasting.
In 2022, rival service LastPass confirmed a major security breach where hackers made off with customer vault backups. Although these vaults were encrypted, older accounts suffered from weaker default master password requirements. This vulnerability allowed cybercriminals to brute-force and decrypt several vaults. Subsequent reports surfaced suggesting that hackers successfully used private keys stolen from LastPass to siphon millions in cryptocurrency from compromised users.
Similarly, in 2021, Australian software developer Click Studios urged users of its Passwordstate platform to urgently reset all credentials. This warning came after hackers compromised the company’s software update pipeline to distribute malware directly to customer networks.
