惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
H
Help Net Security
N
Netflix TechBlog - Medium
Apple Machine Learning Research
Apple Machine Learning Research
P
Proofpoint News Feed
A
About on SuperTechFans
V
V2EX
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
宝玉的分享
宝玉的分享
aimingoo的专栏
aimingoo的专栏
F
Fortinet All Blogs
博客园 - 【当耐特】
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
I
InfoQ
Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
B
Blog RSS Feed
U
Unit 42
The Cloudflare Blog
Y
Y Combinator Blog

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase Backblaze Stops Backing Up Dropbox And Others—Calls It An Improvement
Dashlane Users Locked Out After Password Manager Detects ...
Davey Winder · 2026-06-01 · via Forbes - Consumer Tech
Password Input Field With Padlock

Dashlane comfrim,s brute force attack targeting users

getty

Updated June 2: This article has been updated with details of an official security advisory and customer FAQ regarding the Dashlane Password Manager brute-force attack security incident, along with confirmation that some encrypted password vaults were downloaded by the attacker.

Dashlane users are reporting that their accounts have been temporarily suspended after the password manager confirmed it was targeted by a brute-force attack. The number of affected users has not been disclosed; however, Dashlane has now confirmed that “fewer than 20” encrypted password vaults belonging to personal users were also downloaded by the attacker.

Impacted users received emails that read: “Your account has been temporarily suspended for security reasons as someone has attempted to register a new device and didn’t enter the correct token after several tries.” These users were also advised to contact customer support.

The brute-force attacks appear to have started on Sunday, May 31, when Dashlane confirmed that it was investigating “reports from several users having received an email that their account has been suspended.” Dashlane also said that some users were “experiencing difficulties in logging in to Dashlane after resetting their master password.” Later the same day, Dashlane updated that status message to say that the situation had been resolved, saying that “certain Dashlane user accounts were targeted in a brute force attack by an external party, resulting in the suspension of those accounts as part of Dashlane’s built-in security measures.”

ForbesMy Password Has Been Stolen—What Happens Next?

Dashlane confirms brute-force account attacks.

Dashlane

Attackers Also Downloaded Copy Of A Small Number Of Dashlane Encrypted Password Vaults

I reached out to Dashlane for further clarification and Jordan Fylonenko, its senior director of corporate communications, confirmed that “there is no evidence that Dashlane’s internal system has been impacted.” Fylonenko also advised that Dashlane has now published an official security advisory and customer FAQ, which provides “additional details of the incident, investigation status, impact to user accounts, and steps we’ve taken to protect customers.”

The advisory included further details of the attack itself, noting that the goal was to “brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts.” Brute-force attacks are generally large in nature, and the Dashlane incident appears no different. “Because of the high volume of attempts on user accounts,” the advisory continued, “Dashlane’s security controls automatically locked accounts that were targeted by the attack.”

Dashlane also confirmed that “the attackers were able to download a copy of the encrypted vaults of fewer than 20 personal plan users.” While the number is small, any downloading of encrypted password vaults is likely to cause broader concern among service users. “We have directly notified each of these users,” Dashlane said, adding that anyone who has not had such a message relating to vault risk, “there is no impact to your Dashlane account.”

Without the user’s master password, these downloaded accounts cannot be accessed. Which is good news if you have a strong and unique one, as you should. Less so if you have not taken your master password creation as seriously as you should. That said, Dashlane added: “Our vault encryption ensures that any attempts to gain access to the vault are statistically unlikely to succeed, even over a long period of time.”

What Dashlane Users Should Know About Brute Force Attacks

A brute-force attack, also known as credential-stuffing, occurs when a threat actor uses as many username and password combinations as possible in the hope that one will unlock the account in question. Most often, the credentials being used will have come from dark web marketplaces where databases of leaked and compromised passwords are traded.

This is important for Dashlane users to understand, as it suggests that this incident is part of an opportunistic campaign rather than pointing to the discovery of any security vulnerability with Dashlane itself. This has been made clear by Dashlane itself in postings on X, as well as the previously referenced status messages.

As well as not sharing account passwords, users are advised by Dashlane to turn on two-factor authentication “for an extra layer of security.” There is no need to delete your Dashlane account or to consider this a reason to stop using the service, as password managers remain an important piece of the better security model for most consumers.