Dashlane claims hackers stole part of users' encrypted password databases.
TechCrunch
06-02 23:46
Ai Focus
Dashlane disclosed that hackers bypassed 2FA and stole some users' encrypted password libraries, and the incident may have affected sensitive credentials and encrypted private keys stored in password managers.
Helpful
No.Help

Password manager provider Dashlane disclosed that hackers gained access to some users' encrypted password libraries during a weekend cyberattack. The company stated that attackers brute-forced two-factor authentication mechanisms to gain access to approximately 20 customer accounts and downloaded at least a dozen encrypted files used to store passwords and other sensitive credentials.

Approximately 20 accounts were affected.

The announcement indicates that the attack aimed to bypass 2FA protection on accounts, allowing attackers to register new devices into existing accounts. Dashlane stated that attackers may have used automated tools to quickly try various combinations of numbers, guessing the correct sequence before the one-time CAPTCHA expired.

The company stated that there is currently no evidence that Dashlane's own system was compromised, but it has not yet explained how the attackers breached its two-factor authentication defenses. Dashlane has notified affected users, but did not specify whether these accounts were targeted or disclose the attackers' identities.

The stolen files are still encrypted.

Dashlane states that the downloaded password database is encrypted and cannot be read directly. Decrypting these files requires a master password set by the user. This master password is not uploaded to Dashlane in plaintext, therefore the company itself cannot provide this information directly.

However, the company also cautioned that if users use easily guessed master passwords, the risk of the related password database being cracked offline is higher. This means that even if an attacker obtains encrypted files, users with weak passwords may still face subsequent risks.

Historical cases have impacted crypto assets

Large-scale data breaches are uncommon for password manager companies, but when they involve password vault backups, the impact often lasts a long time. In 2022, LastPass confirmed that customer password vault backups were stolen in an attack. Due to weak master passwords for some early users, some password vaults were subsequently brute-forced.

Subsequently, multiple reports mentioned that hackers may have used the compromised LastPass password database to obtain users' private keys to encrypted assets and commit theft. Earlier, Australian software company Click Studios also experienced a malicious program being implanted in its update mechanism, requiring Passwordstate users to reset all credentials.

Additional information:Dashlane stated that it has taken measures to reduce the risk of similar incidents happening again, but has not yet disclosed the specific measures taken, nor has it stated whether it has received any extortion requests.

Tip
$0
Like
0
Save
0
Views 889
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
The UK's FCA warns Premier League clubs to be cautious about encrypted sponsorships.
The UK's FCA has issued a compliance warning to Premier League clubs regarding encrypted sponsorships, urging them to handle advertising and consumer risk disclosures with caution.
Cryptonews
·2026-06-03 17:27:47
450
Foreign media: UK regulators warn of risks associated with encrypted partnerships among Premier League clubs.
British regulators have warned Premier League clubs to be cautious about working with unauthorized crypto companies, reflecting stricter regulations on crypto marketing and customer acquisition.
AMBCrypto
·2026-06-04 13:26:53
741
Billions Network claims AI agents are impacting advertising models.
Billions Network states that AI agents are undermining traditional web advertising models and driving up demand for on-chain traceability infrastructure.
CoinDesk
·2026-06-03 14:56:03
118
Armstrong claims the stalled US encryption legislation could benefit China.
Brian Armstrong stated that if the United States fails to advance legislation on cryptocurrencies and stablecoins, it may lose the initiative in the fintech competition with China.
Cryptonews
·2026-06-06 07:39:41
109
Foreign media: Saylor claims AI is draining liquidity and suppressing Bitcoin.
Saylor stated that the recent pressure on Bitcoin is mainly due to funds shifting towards AI, while Strategy continues to simultaneously advance its cryptocurrency holding and enterprise AI businesses.
U.Today
·2026-06-04 22:39:10
933