Dashlane explains how attackers managed to download encrypted password vaults
Source
Published
TL;DR
AI GeneratedAttackers targeted Dashlane users by abusing the device enrollment mechanism, sending automated requests to registered email addresses to download encrypted password vaults. Dashlane's security systems detected the attack and locked targeted accounts, preventing widespread data breaches. The attackers managed to access fewer than 20 personal user vaults before the operation was halted. Dashlane's verification process requires a one-time six-digit token sent to the user's email for device enrollment, ensuring security measures are in place to protect user data.