OTHER

Dashlane Discloses Breach: Hackers Accessed Customer Password Vaults

Dashlane, a password management service, has reported that hackers acquired at least a dozen encrypted vaults containing customer passwords during a cyberattack over the weekend.

The company’s website indicates that attackers successfully circumvented their two-factor authentication system, gaining access to about 20 customer accounts. By bypassing this security feature, they were able to download certain customers’ encrypted vaults, safeguarding their passwords and sensitive data.

On its incident page, Dashlane noted that there were no indications of a breach within its systems, although details on how the hackers bypassed the two-factor authentication to access customer accounts remain undisclosed. This security feature is intended to protect accounts from unauthorized access by requiring an additional passcode sent to the account holder’s mobile device.

Dashlane clarified, “The attackers sought to brute-force two-factor authentication (2FA) protections to register new devices on existing user accounts.” The company pointed out that attackers might use automated tools to “quickly input all potential numeric combinations into the system, aiming to guess the right sequence before the temporary [two-factor] security code expires.”

The company has asserted that it has “implemented measures to mitigate the risk of future incidents,” but it did not specify what those measures are.

Dashlane has contacted the roughly 20 customers whose encrypted vaults were affected. It remains uncertain whether these individuals were specifically targeted based on their identities or professions.

Representatives from Dashlane did not respond to inquiries. The company has not revealed whether it has identified the individuals behind the attack or if the hackers communicated with Dashlane regarding demands, such as ransom.

According to their website, the stolen vaults are encrypted and cannot be accessed without the customer’s master password, which is only known to the customer and not stored in plaintext by Dashlane. Nevertheless, Dashlane cautioned that customers with easily guessable master passwords may be at a higher risk of having their vaults cracked and decrypted.

While breaches involving password management companies are rare, they can lead to serious consequences.

In 2022, LastPass confirmed that backups of customer password vaults were stolen during a cyberattack. Although these vaults were secured by customer-specific passwords, the requirements for early users were less strict than today’s standards, which allowed hackers to easily guess some vault passwords. Following this incident, reports emerged of hackers pilfering significant amounts of customers’ cryptocurrency, likely by exploiting private keys stored in compromised LastPass vaults.

The year before, Click Studios, an Australian software firm, warned all users of its primary password manager, Passwordstate, to “reset all credentials” after hackers compromised its software update process to insert malware into customer systems.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.