<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot;]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://infosec.exchange/@briankrebs/116670688015956223" rel="nofollow noopener"><span>https://</span><span>infosec.exchange/@briankrebs/1</span><span>16670688015956223</span></a></p><p>Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for "fewer than 20 personal plan users." Dashlane said there was no evidence of a hack of its own systems, but it hasn't shared yet why or how that 2FA was compromised. The company said “the goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” and that it has already notified affected users.</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts?7194ef805fa2d04b0f7e8c9521f97343">
Just a moment...
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts?7194ef805fa2d04b0f7e8c9521f97343" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://support.dashlane.com/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(support.dashlane.com)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/topic/7f6ca5c4-5f38-4f49-95fd-b3d1d1221731/dashlane-posted-an-update-saying-hackers-brute-forced-its-two-factor-authentication-system-and-gained-access-to-the-encrypted-password-vaults-for-fewer-than-20-personal-plan-users.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 19:03:13 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/7f6ca5c4-5f38-4f49-95fd-b3d1d1221731.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 03 Jun 2026 11:25:44 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 12:01:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/dalias%40hachyderm.io">@<span>dalias</span></a></span> You got it. Put that dusty old bitcoin mining botnet to work on it!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116686065626667050</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116686065626667050</guid><dc:creator><![CDATA[briankrebs@infosec.exchange]]></dc:creator><pubDate>Wed, 03 Jun 2026 12:01:01 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:54:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> Ahhh, that makes sense. So if they have strong passphrases, nothing. But if weak, crackable offline with big resources.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116686038364072886</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116686038364072886</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:54:05 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:51:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/dalias%40hachyderm.io">@<span>dalias</span></a></span> They got access to 20 encrypted vaults. They'd still have to work out the master password for those targeted accounts. Theoretically, that could be done offline, as happened w/ the breach at LastPass, but it took many months for a lot of those stolen vaults to be cracked.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116686026368876910</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116686026368876910</guid><dc:creator><![CDATA[briankrebs@infosec.exchange]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:51:02 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:49:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> "gained access to the encrypted password vaults" sounds like they weren't encrypted.</p><p>Unless they mean the attackers only gained access to what amounts to random bits.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116686020309881307</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116686020309881307</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:49:30 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:48:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/shironeko%40fedi.tesaguri.club">@<span>shironeko</span></a></span> <span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> <br />If they knew the master password then the whole vault is compromised as they got an encrypted offline copy of that too   </p><p>Terrifying.</p><p>I eagerly await updates on this as more facts are discovered…</p>]]></description><link>https://board.circlewithadot.net/post/https://tenforward.social/users/gareth/statuses/116686017561868834</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tenforward.social/users/gareth/statuses/116686017561868834</guid><dc:creator><![CDATA[gareth@tenforward.social]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:48:48 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:43:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> brute-forcing 2FA? Like they brute-forced the 2FA codes? There was no rate limiting? No failure after N tries? That's not really better</p>]]></description><link>https://board.circlewithadot.net/post/https://cosocial.ca/users/pl/statuses/116685996350657481</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cosocial.ca/users/pl/statuses/116685996350657481</guid><dc:creator><![CDATA[pl@cosocial.ca]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:43:24 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:37:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange" rel="nofollow noopener">@<span>briankrebs</span></a></span> the fact that Dashlane allowed 2FA to be brute forced instead of raising timeouts and warning users is what worries me.</p><ul><li>Tho granted, what else did I expect from a <em>proprietary SaaS-only "solution"</em> that literally infringed on John Deere's logo in the past (which I presume was the reason they changed their logo some time ago!)…</li></ul>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/ap/users/116655881384112498/statuses/116685973839994355</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/ap/users/116655881384112498/statuses/116685973839994355</guid><dc:creator><![CDATA[netzblockierer@tech.lgbt]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:37:41 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:37:35 GMT]]></title><description><![CDATA[<span><a href="/user/briankrebs%40infosec.exchange" rel="ugc">@<span>briankrebs</span></a></span> <span><a href="/user/koehntopp%40infosec.exchange" rel="ugc">@<span>koehntopp</span></a></span> I could imagine one scenario where if they allow adding a second device base on only 2fa (stupid) then you can try a lot of users and someone will be hit just by chance and the rate limit would not apply.]]></description><link>https://board.circlewithadot.net/post/https://fedi.tesaguri.club/objects/0318e845-d628-41a3-8e43-05b147ec1b1f</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fedi.tesaguri.club/objects/0318e845-d628-41a3-8e43-05b147ec1b1f</guid><dc:creator><![CDATA[shironeko@fedi.tesaguri.club]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:37:35 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:36:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> <br />Well, there's a recent surge of sites where the default after entering your email is you're being sent a code to that email - THAT is something that would not require knowing the password, but it's also not 2FA (well, not as we'd use that word, anyway)</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/koehntopp/statuses/116685970557048242</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/koehntopp/statuses/116685970557048242</guid><dc:creator><![CDATA[koehntopp@infosec.exchange]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:36:51 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:36:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> Is their 2FA not normal 2FA then?  I'd expect a 6 digit code that changed every 30 seconds or so.. brute forcing that would be incredibly unlikely.</p>]]></description><link>https://board.circlewithadot.net/post/https://toot.hoyle.me.uk/users/tony/statuses/116685967524526062</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://toot.hoyle.me.uk/users/tony/statuses/116685967524526062</guid><dc:creator><![CDATA[tony@toot.hoyle.me.uk]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:36:05 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:35:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/koehntopp%40infosec.exchange">@<span>koehntopp</span></a></span> I had the same question. Seems to me, the only way brute-force is useful as an attack is if you can by default try a large number of possible combinations at once, but they're saying that rate limiting was what caused the affected accounts to get locked out the other day. Something isn't adding up.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116685964196947827</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116685964196947827</guid><dc:creator><![CDATA[briankrebs@infosec.exchange]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:35:14 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:33:50 GMT]]></title><description><![CDATA[<span><a href="/user/briankrebs%40infosec.exchange" rel="ugc">@<span>briankrebs</span></a></span> hmm I'm not familiar with how dashlane works, but how did they reach 2fa? I guess their<br /> master password was weak?]]></description><link>https://board.circlewithadot.net/post/https://fedi.tesaguri.club/objects/6e772b32-45c8-445d-a893-97f55eb0c277</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fedi.tesaguri.club/objects/6e772b32-45c8-445d-a893-97f55eb0c277</guid><dc:creator><![CDATA[shironeko@fedi.tesaguri.club]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:33:50 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:32:53 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> <br />Brute force 2FA...?</p><p>That does not sound like something that should be successfully possible? Wouldn't you have to know the password before that, too?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/koehntopp/statuses/116685954999461107</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/koehntopp/statuses/116685954999461107</guid><dc:creator><![CDATA[koehntopp@infosec.exchange]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:32:53 GMT</pubDate></item><item><title><![CDATA[Reply to Dashlane posted an update saying hackers brute-forced its two-factor authentication system, and gained access to the encrypted password vaults for &quot;fewer than 20 personal plan users.&quot; on Wed, 03 Jun 2026 11:28:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> Brute forcing 2FA seems a bit strange. Never used Dashlane though so I have no idea what methods they might be using. REST endpoint that allows an unlimited amount of 6 digit tries? </p><p>I'm _so_ curious as to how they've managed this.</p>]]></description><link>https://board.circlewithadot.net/post/https://swecyb.com/users/troed/statuses/116685936832121001</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://swecyb.com/users/troed/statuses/116685936832121001</guid><dc:creator><![CDATA[troed@swecyb.com]]></dc:creator><pubDate>Wed, 03 Jun 2026 11:28:16 GMT</pubDate></item></channel></rss>