{"rewrite":{"id":"r_252bf50fabd4c536bbbd3234","clusterId":"c_9154e8cf07cdfb1c54f0e369","slug":"dashlane-says-attackers-stole-encrypted-password-vaults-of-under-20-users","model":"deepseek-v4-flash","headline":"Dashlane Says Attackers Stole Encrypted Password Vaults of Under 20 Users","summary":"On May 31, 2026, Dashlane suffered a brute force attack targeting specific user accounts. Attackers bypassed two-factor authentication and registered new devices, downloading encrypted password vaults for fewer than 20 individual plan users. Dashlane locked affected accounts, restored access, and says the vaults' encryption makes decryption statistically improbable without the master password.","whyItMatters":"The incident confirms that even with zero-knowledge architecture and strong encryption, the device registration flow can be exploited to exfiltrate encrypted vaults, though the small number of affected users and Dashlane's encryption claims limit the practical risk.","webCardHtml":"\u003cp\u003eDashlane disclosed on June 5 that a brute force attack on May 31 targeted the device registration API endpoint, allowing attackers to register new devices on existing accounts after bypassing two-factor authentication. The attackers downloaded encrypted password vaults for fewer than 20 individual plan users. Dashlane's automated system locked the targeted accounts, and access has been restored. The company says the vaults use Argon2, AES-256-CBC, and HMAC-SHA256 encryption, and that without the master password-which Dashlane does not store-decryption is statistically infeasible even over an extended period. Dashlane has blocked the threat actor's traffic and implemented additional security measures. The investigation concluded on June 4 with no evidence of impact on internal systems or additional user accounts.\u003c/p\u003e","blueskyPost":"Dashlane says attackers stole encrypted password vaults for fewer than 20 users via a brute force attack on the device registration flow. The company claims the vaults' encryption makes decryption without the master password statistically improbable.","twitterPost":"Dashlane says attackers stole encrypted password vaults for fewer than 20 users via a brute force attack on the device registration flow. The company claims the vaults' encryption makes decryption without the master password statistically improbable.","threadsPost":null,"newsletterBlurb":"Dashlane disclosed a brute force attack on May 31 that targeted the device registration API endpoint. Attackers bypassed two-factor authentication and downloaded encrypted password vaults for fewer than 20 individual plan users. Dashlane says the vaults' encryption makes decryption without the master password statistically improbable, and no additional impact has been found.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260605-dashlane-how-attackers-managed-encrypted-password/\",\"title\":\"Password Manager Dashlane Explains How It Suffered a Cyber Attack and Had Encrypted Password Vaults Stolen\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4167,"outputTokens":597,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1780641258,"createdAt":"2026-06-05T06:27:23.000Z","publishedAt":"2026-06-05T06:31:15.000Z","updatedAt":"2026-06-05T06:31:15.000Z"},"cluster":{"id":"c_9154e8cf07cdfb1c54f0e369","canonicalTitle":"パスワードマネージャーのDashlaneがサイバー攻撃を受け暗号化パスワード保管庫を盗まれた経緯を説明","representativeArticleId":"a_d60cebd4db599ace589fb9b9","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-06-05T05:45:00.000Z","lastSeenAt":"2026-06-05T05:45:00.000Z","updatedAt":"2026-06-05T06:31:15.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260605-dashlane-how-attackers-managed-encrypted-password/","title":"パスワードマネージャーのDashlaneがサイバー攻撃を受け暗号化パスワード保管庫を盗まれた経緯を説明"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":["On May 31, 2026, attackers targeted Dashlane's device registration API endpoint in a brute force attack.","The attackers bypassed two-factor authentication, registered new devices, and downloaded encrypted password vaults for fewer than 20 individual plan users.","Dashlane locked the affected accounts and restored access, stating the vaults' encryption (Argon2, AES-256-CBC, HMAC-SHA256) makes decryption statistically improbable without the master password.","Dashlane blocked the threat actor's traffic and added security measures, concluding the investigation on June 4 with no evidence of impact on internal systems or additional accounts."]}
