:

DASHLANE USERS LOCKED OUT IN BRUTE FORCE ATTACK

INDUSTRY DESK2 MIN READ
TUE, JUN 2, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Password manager Dashlane has confirmed that hackers used brute force attacks to compromise approximately 20 user password vaults. Multiple users report being locked out of their accounts following login attempts from unfamiliar locations and devices.

Dashlane disclosed the security incident after users experienced unauthorized access attempts on their accounts. The attacks involved repeated login tries—a brute force method—targeting a limited number of password vaults stored on the platform. Affected users received notifications of login attempts from distant geographic locations and unrecognized devices. Dashlane locked these accounts as a security measure to prevent further unauthorized access. What happened The brute force attacks exploited weaknesses in account authentication, allowing attackers to attempt numerous password combinations until gaining access. While Dashlane has not disclosed the exact number of compromised accounts, the company confirmed approximately 20 password vaults were stolen during the incident. Company response Dashlane has not yet published a detailed public statement about the full scope of the breach or remediation steps. Users locked out of their accounts are being directed to recover access through the company's standard recovery procedures. What users should know Password manager breaches carry heightened risk, as compromised vaults potentially expose credentials for multiple services. Users with Dashlane accounts should: - Change passwords for critical accounts, particularly email and financial services - Enable multi-factor authentication where available - Monitor accounts for suspicious activity - Consider using a different password manager if trust has been affected This incident highlights ongoing security challenges facing password management platforms, which remain high-value targets for attackers. The relatively small number of compromised vaults suggests Dashlane's security measures contained the breach, though questions remain about how attackers obtained credentials for the targeted accounts. Dashlane has not announced whether the attack exploited a vulnerability in its service or relied on compromised credentials obtained elsewhere.

■ SOURCES

EngadgetBleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

2H AGOSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

4H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

9H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

12H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.