Hackers stole encrypted password vaults from about 20 Dashlane customers by brute-forcing the company's two-factor authentication (2FA) system over the weekend before June 2, 2026 [1]. Dashlane announced the breach publicly and notified affected users on June 2 [1].
The attackers did not breach Dashlane’s internal systems. Instead, they accessed customer accounts by rapidly submitting numeric codes to defeat 2FA protections. Dashlane said the goal was to brute-force 2FA to register new devices on existing accounts. They added that the hackers likely used automated software to send every possible number combination in a trial-and-error attack [1, 2].
Security controls automatically locked targeted accounts after detecting the high-volume login attempts, but the hackers still obtained copies of encrypted vaults belonging to roughly 20 users [2]. Dashlane said the stolen vaults remain encrypted and cannot be decrypted without each customer’s master password, which the company does not store [1, 2]. However, the company warned users with weak or easily guessed master passwords may be at risk of vault decryption [1, 2].
Dashlane has taken unspecified measures to block the threat actor’s traffic and prevent similar incidents in the future [1, 2]. The company recommended all users review their device associations, enable two-factor authentication, and choose stronger master passwords to better protect their accounts [2].
Dashlane did not detail how the attackers defeated 2FA protections or comment on any ransom demands [1]. The breach highlights vulnerabilities in 2FA systems when subjected to rapid automated attacks.
Dashlane continues to monitor the situation and urge customers to update security settings to reduce risk.