Dashlane published an opaque advisory warning that attackers obtained 20 encrypted user vaults via a brute-force attack on two-factor authentication, with users reporting lack of direct notification and confusing details.
<p>There’s a lot that doesn’t add up in a security advisory password manager Dashlane published Monday, warning that attackers managed to obtain 20 encrypted user vaults.</p>
<p>“Starting on Sunday, May 31, 2026, an external party launched a brute force attack against certain Dashlane user accounts,” the company <a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts">said</a>. “The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts.”</p>
<h2>Hello, Dashlane, anybody home?</h2>
<p>A Dashlane user who received such a 2FA request provided this screenshot of the notification, which arrived on Sunday.</p><p><a href="https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/#comments">Comments</a></p>
# Dashlane issues opaque advisory warning 20 encrypted vaults were stolen
Source: [https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/](https://arstechnica.com/security/2026/06/dashlane-issues-opaque-advisory-warning-20-encrypted-vaults-were-stolen/)
There’s a lot that doesn’t add up in a security advisory password manager Dashlane published Monday, warning that attackers managed to obtain 20 encrypted user vaults\.
“Starting on Sunday, May 31, 2026, an external party launched a brute force attack against certain Dashlane user accounts,” the company[said](https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts)\. “The goal of the attack was to brute\-force two\-factor authentication \(2FA\) protections to allow the attacker to register new devices on existing user accounts\.”
## Hello, Dashlane, anybody home?
A Dashlane user who received such a 2FA request provided this screenshot of the notification, which arrived on Sunday\.
[](https://cdn.arstechnica.net/wp-content/uploads/2026/06/dashlane-notification.jpg)
The UK\-based user was concerned and contacted Dashlane through a support bot\. Ultimately the user got no information about why the notification was sent\.
“Then \[I\] discovered this news from Mastodon infosec and not Dashlane themselves,” the user told me\. “Currently trying to find out what has happened\! Because how can you trigger a 2fa request if you haven’t got the password 1st? As a paying customer I think I should have known about this from Dashlane and not Mastodon infosec folks\.”
Scores of social media discussions are filled with similar comments from users who also don’t understand the basic mechanics of this attack\. Typically, 2FA protections take the form of a one\-time password generated by an authentication app or sent by text or email\. They’re typically six digits long and change every 45 or so seconds, although as the notification above indicates, the code remained valid for three hours\.
Brute\-forcing is a trial\-and\-error method that rapidly submits every possible combination until landing on the right one\. Under these assumptions, there would be 1 million possible passcodes\. A successful breach would require a statistically significant percentage of them to be entered within the three\-hour window\.
While the resources needed to bombard Dashlane servers with that volume of guesses in such a short period of time are possible, they’re not commonly found in usual brute\-force attacks\. Dashlane doesn’t explicitly say it placed a rate limit on the number of submissions a user can make, although it appears likely based on language in the advisory saying “Because of the high volume of attempts on user accounts, Dashlane’s security controls automatically locked accounts that were targeted by the attack\.” Even assuming there was no rate limiting, it’s hard to imagine Dashlane servers not at least temporarily choking when receiving 150,000 or more submissions in an hour or so\.
Dashlane disclosed a coordinated brute-force attack where threat actors abused device enrollment APIs to send one-time codes across thousands of accounts simultaneously, successfully downloading encrypted password vaults for fewer than 20 users before the attack was shut down.
LastPass is notifying users of a data breach caused by a compromise at its third-party vendor Klue, exposing customer names, email addresses, and support case data, but not password vaults.
This security news roundup covers the latest LastPass data breach via a partner, predictive policing in Bristol, Dialog group data exposure, Anthropic's AI model negotiations with the White House, OpenAI's new GPT-5.5-Cyber and open-source patching initiative, and other security stories.
A massive breach exposed credentials for thousands of sensitive networks, including a NATO defense contractor, with attackers using a 45-GPU cluster to crack VPN authentication hashes and compromise Active Directory environments.
A June 2024 intrusion disclosed in April 2026 saw attackers abuse a compromised third-party OAuth app to access Vercel’s internals and expose customer environment variables, spotlighting OAuth supply-chain risks and platform secret-handling flaws.