Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Breach Dashlane’s 2FA, Download Encrypted Vaults

Hackers Breach Dashlane’s 2FA, Download Encrypted Vaults

Posted on June 5, 2026 By CWS

Dashlane recently revealed a security breach where hackers successfully bypassed two-factor authentication (2FA) to register unauthorized devices and download encrypted password vaults. This incident affected fewer than 20 personal users, with an investigation confirming no further impact on Dashlane’s internal systems.

Details of the Breach

Beginning May 31, 2026, Dashlane faced a brute-force attack targeting user accounts through its device registration API. The attackers focused on guessing the 6-digit tokens sent via email or generated by authenticator apps. Despite Dashlane’s security measures triggering account lockouts, the attackers managed to register new devices for a small subset of accounts.

Attack Methodology

The attackers exploited Dashlane’s device registration process, which occurs when a user adds a new device. By brute-forcing the 6-digit tokens, they were able to complete the registration and download encrypted vaults without detection. Dashlane promptly notified all affected users.

Although the vaults were downloaded, Dashlane asserts that the data remains secure. The Master Password, vital for accessing vault contents, is not stored or transmitted in plaintext, adhering to Dashlane’s zero-knowledge architecture. The encryption technology used, including Argon2, AES-256-CBC, and HMAC-SHA256, makes brute-forcing the Master Password highly improbable.

Dashlane’s Response and Future Measures

On June 4, 2026, Dashlane finalized its investigation, confirming no broader customer impact. The company took several measures, such as blocking malicious traffic, reinstating affected accounts, and enhancing the security of the device registration process. These steps aim to prevent similar incidents in the future.

This breach highlights the importance of robust 2FA configurations and maintaining strong Master Passwords. Users are encouraged to follow best practices to ensure their accounts remain secure against potential threats.

For more updates, follow us on Google News, LinkedIn, and X.

Cyber Security News Tags:2FA breach, AES-256-CBC, API security, Argon2, brute-force attack, Cybersecurity, Dashlane, device registration, encrypted vaults, HMAC-SHA256, Master Password, password security, Remediation, security incident, zero-knowledge architecture

Post navigation

Previous Post: VECT 2.0 Ransomware Poses Severe Data Recovery Risks
Next Post: Trump’s AI Cybersecurity Order: Industry Insights

Related Posts

New Harrods Data Breach Exposes 430,000 Customer Personal Records New Harrods Data Breach Exposes 430,000 Customer Personal Records Cyber Security News
Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment Cyber Security News
Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment Cyber Security News
Microsoft Unveils a New Tool to Migrate from Slack to Microsoft Teams Microsoft Unveils a New Tool to Migrate from Slack to Microsoft Teams Cyber Security News
Node.js 25.5.0 Released Update Root Certificates and New Command-Line Flags Node.js 25.5.0 Released Update Root Certificates and New Command-Line Flags Cyber Security News
Here’s How to Spot Them Early Here’s How to Spot Them Early Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark