Dashlane says an external threat actor carries out a brute-force attack targeting two-factor authentication (2FA) for a small number of customer accounts. The company reports the attack starts on May 31 and focuses on some personal-plan users, with Dashlane stating fewer than 20 accounts have their encrypted password vaults downloaded. Dashlane describes the method as using brute-force attempts against 2FA to bypass protections and obtain copies of users’ encrypted vault data. The company also says its internal systems are not compromised, and it finds no evidence that attackers accessed Dashlane’s infrastructure.

Dashlane says it responds through its security controls, including automatic account lockouts that are triggered for a wider set of targeted users as attempts continue. Earlier user reports of account suspension notices and login problems lead Dashlane to acknowledge the incident on May 31. Across outlets, the core reported impact is limited to encrypted vault downloads from a small number of personal subscription accounts, rather than exposure of plaintext passwords. Ars Technica adds context that attackers’ strategy involves targeting many accounts to improve the likelihood of success.