Dashlane Discloses Security Breach: Hacker Exploits Flaw to Access Encrypted Vaults
Password Manager Dashlane Reveals How a Hacker Stole Encrypted Vaults

Image: Pcmag
Dashlane, a prominent password manager, reported a security breach where a hacker exploited a flaw in its device registration process, allowing access to encrypted vaults of fewer than 20 users. The attack involved a brute force attempt on the two-factor authentication system, where the hacker could download vaults by guessing a six-digit verification code.
- 01The breach affected fewer than 20 users, with encrypted vaults stolen.
- 02The hacker targeted Dashlane's device registration flow, bypassing the master password requirement.
- 03Dashlane's two-factor authentication system was compromised through brute force attempts on six-digit codes.
- 04The company is implementing additional verification layers and network protections to prevent future attacks.
- 05Dashlane ensures that master passwords are not stored on its servers, keeping vault data encrypted.
Advertisement
In-Article Ad
Dashlane, a leading password manager, revealed that a hacker exploited a vulnerability in its online login system, leading to the theft of encrypted vaults from fewer than 20 users. The incident occurred on a Sunday, and although Dashlane initially reported a brute force attack on its two-factor authentication (2FA) system, details remained unclear. The hacker was able to bypass the master password requirement by targeting the device registration flow, where entering a six-digit verification code was sufficient to access the encrypted vaults. This flaw allowed the hacker to potentially guess the code, as there are one million possible combinations. Dashlane has since stated that no master passwords were compromised, meaning the vault data should remain encrypted. To mitigate future risks, the company plans to add more verification layers and has implemented network-level protections to filter out malicious traffic. Dashlane emphasizes that its encryption methods ensure vault data remains secure despite the breach.
Advertisement
In-Article Ad
The breach raises concerns about the security of password management systems and the potential for unauthorized access to sensitive information.
Advertisement
In-Article Ad
Reader Poll
How concerned are you about the security of password managers?
Connecting to poll...
More about Dashlane
Read the original article
Visit the source for the complete story.






