Apps & Consumer
Dashlane confirms hackers brute-forced 2FA to access accounts
Dashlane confirmed hackers brute-forced its two-factor authentication system, accessing about 20 customer accounts and stealing at least a dozen encrypted password vaults.
Dashlane has confirmed a security incident in which hackers brute-forced the company’s two-factor authentication system. According to the company, the attack granted hackers access to about 20 customer accounts. Dashlane stated that during this cyberattack, hackers have obtained at least a dozen encrypted vaults used for storing customer passwords. By defeating the two-factor mechanism, the attackers were able to download copies of these vaults, which store passwords and other sensitive credentials. The company has since notified the 20 or so customers whose encrypted vaults were stolen.
Dashlane stated on its website that there is no evidence of compromise of Dashlane’s own systems, emphasizing that the breach was limited to the targeted user accounts. Two-factor authentication is a security feature that protects accounts from being accessed with just a username and password, typically by requiring an additional passcode. According to the company, the goal of the attack was to brute-force these protections to allow the attacker to register new devices on existing user accounts. To achieve this, the attackers used automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires.” Dashlane noted that it has taken steps to mitigate the risk of future incidents, though it did not specify what those measures entail.
The stolen vaults are scrambled and cannot be read without each customer’s master password, which is not uploaded to Dashlane in plaintext. However, the company warned that customers with easily guessed master passwords may be at greater risk of decryption. While security breaches at password management firms remain rare, this event follows previous high-profile industry incidents. In 2022, LastPass confirmed that customer password vault backups were stolen during a cyberattack. Additionally, a year earlier, Australian software house Click Studios warned users of its Passwordstate product to reset all credentials after hackers compromised its software update mechanism to plant malware on customer systems.
Why it matters
This incident highlights the vulnerability of two-factor authentication systems to brute-force attacks, serving as a reminder that even security-focused tools are not immune to sophisticated credential-stuffing methods.