News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Jun 4, 2026 at 20:02 Big Tech Rising Hot

Dashlane explains how attackers managed to download encrypted password vaults

By targeting large numbers of users, attackers increased their chances of success.

Signal weather

Rising

Momentum is building quickly, so this card is a good early entry point into the topic.

By Dan Goodin Original source
Dashlane explains how attackers managed to download encrypted password vaults

Dashlane said that attackers mounted a coordinated hacking campaign against a large base of its users in an attempt to recover as many encrypted password vaults as possible. The password manager provider said fewer than 20 personal user vaults were downloaded before it shut down the operation. In a campaign that started Sunday, the unknown threat actor abused the mechanism that allows Dashlane users to add new devices, such as computers or phones, to their accounts. By abusing Dashlane's programming interfaces for device enrollment, the attackers sent requests to large numbers of existing users’ registered email addresses. In an update published Thursday, Dashlane wrote: The threat actor targeted the API endpoints for device registration and used a brute force attack to send a large volume of automated requests to those endpoints. In response, Dashlane’s automated security systems operated as intended, triggering an automatic lockout of the targeted accounts to protect those users. Before the attack was fully mitigated, the threat actor was able to brute force and generate valid tokens for fewer than 20 personal plan customers, allowing them to register a new device on those accounts and download copies of users’ encrypted vaults. The flow and strategy of the attack When a user installs the Dashlane app on a new device and attempts to enroll it in their existing account, Dashlane first verifies the account holder's identity. This verification is completed by sending a one-time six-digit token to the user’s registered email address (or, for users who have enabled two-factor authentication, by validating a six-digit code generated by their authentication app).Read full article Comments

Stay on the signal

Follow Dashlane explains how attackers managed to download encrypted password vaults

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

Fresh coverage with immediate momentum.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Attackers, and Attackers Increased, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

Jun 8, 2026 at 11:00 Ars Technica

The weather and climate science AI revolution isn’t revolutionary

Machine learning has its limits—how is it being used?

Jun 8, 2026 at 09:11 SecurityLab

Шесть цифр — и ваши пароли у чужого. Хакеры взломали Dashlane через коды подтверждения устройств

Брутфорс-атака на Dashlane оказалась проще, чем звучит в пресс-релизах.

Jun 7, 2026 at 19:34 Ars Technica

RIP Anthony Head: Our 10 favorite moments of Buffy's Giles

Head's true genius—and that of his character, Giles—lay in quietly filling in the gaps in every scene

Jun 7, 2026 at 11:08 Ars Technica

School shooting survivor sues AI gun detection firm after system failed to spot weapon

How accurate does an AI system need to be?

Jun 6, 2026 at 11:15 Ars Technica

Some ancient microbes frozen with Ötzi the Iceman are still growing

What’s the difference between a person, an artifact, and an ecosystem?

Jun 4, 2026 at 20:02 Ars Technica

Dashlane explains how attackers managed to download encrypted password vaults

By targeting large numbers of users, attackers increased their chances of success.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

2

Related articles

More stories that share tags, source, or category context.

SecurityLab Jun 8, 2026 at 09:11 Cybersecurity
Rising Hot

Шесть цифр — и ваши пароли у чужого. Хакеры взломали Dashlane через коды подтверждения устройств

Брутфорс-атака на Dashlane оказалась проще, чем звучит в пресс-релизах.

Signal weather

Momentum is building quickly, so this card is a good early entry point into the topic.

Why now

Fresh coverage with immediate momentum.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page