Password manager Dashlane has disclosed how attackers successfully downloaded encrypted password vaults from its users by targeting large numbers of accounts to increase odds of success.
Dashlane published a detailed explanation of the breach affecting a portion of its user base, clarifying the mechanics of how attackers obtained encrypted vault files.
The company confirmed that attackers used a brute-force approach, targeting many user accounts simultaneously. This mass-scale strategy allowed them to bypass security measures through sheer volume, increasing the statistical likelihood of gaining access to at least some accounts.
The attackers downloaded encrypted password vaults—files containing usernames, passwords, and other sensitive data stored in encrypted form. However, Dashlane emphasized that the vaults remain encrypted and inaccessible without the master password.
"The attackers obtained encrypted vault files, not plaintext passwords," Dashlane stated in its explanation. The company stressed that its encryption architecture means stolen vaults alone cannot expose user credentials unless attackers successfully crack the encryption or obtain master passwords through other means.
Dashlane recommended affected users reset their master passwords and enable two-factor authentication. The company also suggested users monitor their accounts for suspicious activity and change passwords for critical accounts accessed through the platform.
The password manager did not disclose the exact number of users impacted or provide a precise timeline for when the breach occurred. Dashlane has been working with security researchers and law enforcement to investigate the incident.
This breach highlights the ongoing security risks even for password managers, which face significant pressure from attackers seeking to compromise high-value targets. While Dashlane's encryption provided a protective layer, the compromise of encrypted vaults—even without immediate decryption—represents a security incident that could pose risks if attackers gain computational resources to crack encryption or obtain additional information.
AegisAI, a security startup founded by former Google executives, secured $36 million in funding to deploy AI agents that detect sophisticated spear phishing attacks.
The US government issued an updated advisory warning that Iranian hackers are actively disrupting critical infrastructure systems used by American water and energy providers.
Apple has published SOC 3 audit reports for its Private Cloud Compute infrastructure, providing third-party verification of security controls for on-device AI processing that routes some tasks to Apple servers.
A developer discovered their coding interview assignment included hidden malware designed to execute via Git hooks. The sophisticated setup raised questions about interview practices and candidate vetting.