Dashlane said an external threat actor targeted its device-registration and two-factor authentication workflow, triggering widespread account lockouts and authentication problems before successfully registering unauthorized devices on fewer than 20 personal-plan accounts. The company said the attacker used high-volume brute-force attempts against 6-digit 2FA tokens tied to new-device enrollment, then downloaded copies of affected users’ encrypted password vaults, while maintaining that Dashlane’s internal infrastructure was not breached. Users had first reported suspicious new-device emails, login attempts from countries including Russia and Korea, and unusual suspension notices that briefly looked like phishing, prompting criticism of Dashlane’s initial communications and status-page updates.
After completing its investigation, Dashlane said it blocked malicious traffic, restored locked accounts, notified affected users, and added stronger protections around device registration, with further verification steps planned. The company said the stolen vaults remain protected by its zero-knowledge design because decryption still requires each user’s master password, and reporting noted that the practical risk is highest for victims who used weak or reused master passwords that could be cracked offline. Security coverage compared the incident with the 2022 LastPass breach, but noted Dashlane encrypts all vault fields and automatically upgrades key-strengthening settings, reducing the likelihood of successful decryption for users with strong, high-entropy master passwords.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Following the investigation, Dashlane said it implemented stronger network- and product-level protections around device registration and related API endpoints, and planned extra verification steps for new device enrollment.
On June 4, 2026, Dashlane said it had completed its investigation and explained that the attacker brute-forced 6-digit 2FA tokens against the device registration API to enroll unauthorized devices. The company said it had blocked malicious traffic, restored locked accounts, and confirmed no compromise of internal systems or broader customer impact.
Dashlane disclosed that the attackers succeeded in a small number of cases, registering unauthorized devices and downloading encrypted password vault copies from fewer than 20 personal plan users. Dashlane said affected users were directly notified and that the vaults remain encrypted under users' master passwords.
On June 1, Dashlane updated its status page to move the incident from resolved to monitoring while continuing to add protections. Reports said some users were still seeing login issues at that time.
Dashlane said it investigated the issue later on May 31, marked the incident resolved, and restored affected accounts that had been suspended as a defensive measure. Some reports noted users still experienced access problems afterward.
After users reported suspension emails and login problems, Dashlane first acknowledged the incident on May 31 and said it was investigating. The company stated the lockouts were triggered by automated security controls and that there was no evidence its internal systems were compromised.
Dashlane said an external threat actor began a high-volume brute-force campaign on May 31, 2026 targeting certain user accounts and device registration workflows in an attempt to bypass two-factor authentication and register unauthorized devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
18 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcearstechnica.com
Open sourcesupport.dashlane.com
Open sourcetheregister.com
Open sourcereddit.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.