Dashlane claims hackers stole part of users' encrypted password databases.
TechCrunch
06-02 23:46
Ai Focus
Dashlane disclosed that hackers bypassed 2FA and stole some users' encrypted password libraries, and the incident may have affected sensitive credentials and encrypted private keys stored in password managers.
Helpful
No.Help

Password manager provider Dashlane disclosed that hackers gained access to some users' encrypted password libraries during a weekend cyberattack. The company stated that attackers brute-forced two-factor authentication mechanisms to gain access to approximately 20 customer accounts and downloaded at least a dozen encrypted files used to store passwords and other sensitive credentials.

Approximately 20 accounts were affected.

The announcement indicates that the attack aimed to bypass 2FA protection on accounts, allowing attackers to register new devices into existing accounts. Dashlane stated that attackers may have used automated tools to quickly try various combinations of numbers, guessing the correct sequence before the one-time CAPTCHA expired.

The company stated that there is currently no evidence that Dashlane's own system was compromised, but it has not yet explained how the attackers breached its two-factor authentication defenses. Dashlane has notified affected users, but did not specify whether these accounts were targeted or disclose the attackers' identities.

The stolen files are still encrypted.

Dashlane states that the downloaded password database is encrypted and cannot be read directly. Decrypting these files requires a master password set by the user. This master password is not uploaded to Dashlane in plaintext, therefore the company itself cannot provide this information directly.

However, the company also cautioned that if users use easily guessed master passwords, the risk of the related password database being cracked offline is higher. This means that even if an attacker obtains encrypted files, users with weak passwords may still face subsequent risks.

Historical cases have impacted crypto assets

Large-scale data breaches are uncommon for password manager companies, but when they involve password vault backups, the impact often lasts a long time. In 2022, LastPass confirmed that customer password vault backups were stolen in an attack. Due to weak master passwords for some early users, some password vaults were subsequently brute-forced.

Subsequently, multiple reports mentioned that hackers may have used the compromised LastPass password database to obtain users' private keys to encrypted assets and commit theft. Earlier, Australian software company Click Studios also experienced a malicious program being implanted in its update mechanism, requiring Passwordstate users to reset all credentials.

Additional information:Dashlane stated that it has taken measures to reduce the risk of similar incidents happening again, but has not yet disclosed the specific measures taken, nor has it stated whether it has received any extortion requests.

Tip
$0
Like
0
Save
0
Views 882
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
DAXA in South Korea tightens key management for encrypted APIs
DAXA South Korea has introduced new rules requiring member exchanges to strengthen API key monitoring, identity verification, and IP whitelist management, as regulators increase scrutiny of automated trading.
crypto.news
·2026-05-29 17:06:50
544
Mastercard receives New York BitLicense to advance encrypted payments.
Mastercard has obtained a BitLicense in New York State and plans to expand its business in crypto payments, stablecoins, and tokenized asset settlement.
AMBCrypto
·2026-05-29 11:47:56
833
The UK's FCA warns Premier League clubs to be cautious about encrypted sponsorships.
The UK's FCA has issued a compliance warning to Premier League clubs regarding encrypted sponsorships, urging them to handle advertising and consumer risk disclosures with caution.
Cryptonews
·2026-06-03 17:27:47
441
Foreign media: North Korean hackers steal $577 million in two attacks.
Foreign media reports that the North Korean Lazarus group attacked crypto protocols twice in April, stealing a total of $577 million, exposing the risks of DeFi multisignature and social engineering.
crypto.news
·2026-05-29 19:38:39
135
Foreign media: UK regulators warn of risks associated with encrypted partnerships among Premier League clubs.
British regulators have warned Premier League clubs to be cautious about working with unauthorized crypto companies, reflecting stricter regulations on crypto marketing and customer acquisition.
AMBCrypto
·2026-06-04 13:26:53
733