As cited
Copy frozen at (site build).
breaches incidents
Dashlane explains how attackers managed to download encrypted password vaults
Dashlane disclosed a coordinated attack where threat actors exploited the device enrollment API to brute force access tokens and download encrypted password vaults from fewer than 20 user accounts before automated security systems shut down the operation. The attackers abused the mechanism that allows users to register new devices by sending high-volume automated requests to API endpoints, bypassing initial identity verification steps. Dashlane's defenses triggered account lockouts to halt the attack, and the downloaded vaults remain encrypted.
Why it matters: Dashlane users should enable two-factor authentication (2FA) if not already active, as it would have required attackers to obtain a second authentication factor beyond the email token that was successfully brute forced.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Dashlane explains how attackers managed to download encrypted password vaults
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Dashlane explains how attackers managed to download encrypted password vaults
Dashlane stated that attackers abused its device enrollment application programming interface (API) to request one time tokens for many user accounts. The company explained that fewer than twenty personal plan vaults were downloaded before the attack was halted.
Why it matters: Dashlane personal plan users whose accounts were targeted may have had their encrypted vaults copied, so practitioners should review device enrollment logs and enforce multi factor authentication for account recovery.
- Source published
- First seen by Cybersecurity Tracker