Connect with us

News

Password manager Dashlane says hackers stole some customers’ password vaults

info

Published

on

Password.jpg

Password manager maker Dashlane says hackers have obtained at least a dozen encrypted vaults used for storing customer passwords during a weekend cyberattack.

The company said on its website that hackers brute-forced the company’s two-factor authentication system, granting the hackers access to about 20 customer accounts. By defeating its two-factor mechanism, the hackers were able to download a copy of certain customers’ encrypted vaults, which store their passwords and other sensitive credentials.

Dashlane said on its incident page that there was no evidence of compromise of its own systems, but it has not yet said how the hackers were able to defeat its two-factor protections in order to access customer accounts. Two-factor is a security feature that protects accounts from being accessed with just a stolen username and password, typically by requiring an additional passcode to be sent to the phone of the account holder.

“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” said Dashlane. The company said that attackers can use automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires.”

The company said it has “taken steps to mitigate the risk of future incidents,” without saying what those were.

Dashlane said it has notified the 20 or so customers whose encrypted vaults were stolen. It’s not yet clear if the specific customers were targeted for a reason, such as because of who they are or what they do for a living.

Spokespeople for Dashlane did not respond to a request for comment. The company has not said if it knows who targeted its customers, or if the hackers contacted Dashlane with demands, such as a ransom.

The stolen vaults are scrambled and cannot be read without the customer’s master password, which is only known by the customer and is not uploaded to Dashlane in plaintext, the company’s website says. But Dashlane said that customers with an easily guessed master password may be at greater risk of having it guessed and their password vaults decrypted.

Data breaches affecting password manager companies are rare, but can have lasting consequences.

In 2022, LastPass confirmed that customer password vault backups were stolen during a cyberattack. While the vaults were protected with passwords only known to the customer, the password requirements for early customers were far weaker than the later standard, allowing hackers to brute-force and easily guess the passwords of some customers’ vaults. There have been several reports of hackers stealing vast amounts of customers’ crypto, likely by using private keys stored in stolen LastPass vaults that had their master passwords cracked following the breach.

A year earlier, Australian software house Click Studios warned all of its customers who use its flagship password manager, Passwordstate, to “reset all credentials” after hackers compromised its software update mechanism to plant malware on customer systems.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

2027: SDP guber primary breached electoral act, void ab initio – Wadada’s associate

info

Published

on

By

SDP guber.jpg

A legal practitioner, Obere A. Kana, Esq., has declared the Social Democratic Party (SDP) governorship primary election conducted in Nasarawa State on September 5, 2026, invalid, alleging that the exercise contravened key provisions of the Electoral Act, 2026.

Kana, who is an associate of Senator Ahmed Aliyu Wadada, the All Progressives Congress (APC) governorship candidate, made the assertion in a statement issued in Keffi.

He alleged that the SDP violated Sections 33 and 82(1) of the Electoral Act in the process leading to the conduct of the primary.

According to Kana, the party had initially submitted Musa Adamu Angba’s name to the Independent National Electoral Commission (INEC) as its governorship candidate pursuant to Section 29(1) of the Act, after which the Commission published Angba’s particulars on August 29, 2026, in accordance with Section 29(3).

Recommended

Kana, however, said Angba had earlier withdrawn his candidature through an affidavit sworn before the Federal High Court in Abuja on June 10, 2026, reportedly in favour of Mohammed Abubakar Adamu.

He argued that Section 33 of the Electoral Act requires a political party to conduct a fresh primary within 14 days of a candidate’s withdrawal in order to nominate and submit a replacement.

Kana maintained that the SDP’s decision to conduct its replacement primary on September 5, more than 14 days after the alleged withdrawal, amounted to a breach of the statutory requirement and rendered the exercise “null and void ab initio.”

He also challenged the notice given by the party to INEC ahead of the primary, citing Section 82(1), which requires political parties to notify the Commission at least 21 days before conducting primaries.

He said the SDP’s notice, dated August 24, 2026, for a primary scheduled for September 5, provided only 13 days’ notice.

Citing Section 82(6), Kana argued that failure to comply with the mandatory notice requirement invalidates the primary.

He further referenced Section 88(3), which, according to him, prevents a candidate produced through such an invalid process from contesting the election.

“There are various precedents decided by superior courts on this,” Kana said, insisting that the alleged breaches raise significant legal questions over the validity of the SDP primary and the candidacy of its eventual flag bearer.

He urged stakeholders to examine the circumstances surrounding the primary in light of the relevant provisions of the Electoral Act and existing judicial precedents.

Continue Reading

News

Plateau attacks: MYM raises alarm over ethnic threat targeting Mwaghavul people

info

Published

on

By

1 14.jpg

The leadership of the Mwaghavul Youth Movement, MYM, has raised alarm over what it described as a dangerous ethnic threat targeting the Mwaghavul people of Mangu Local Government Area of Plateau State.

The MYM was reacting to a widely circulated report in which suspected bandits who abducted two clergymen along the Barkin Ladi-Bokkos road last week reportedly said they would have killed one of the pastors if he turned out to be either Mwaghavul or Berom.

Pastor Gabriel Dipak was abducted alongside Pastor Emmanuel Hills, who was later killed by their abductors.

After his release, Dipak told journalists in an interview that the bandits told him they would have killed him instantly if he were either Mwaghavul or Berom.

Recommended

Expressing concern over the alleged ethnic threat in a statement issued on Saturday by its Director of Public Affairs, Tubwot Joël Sunday, the MYM said it was disturbing that members of the ethnic group would be targeted by terrorists and bandits.

The group said such threats should not be dismissed as ordinary banditry, arguing that they showed that the Mwaghavul people were being profiled and targeted for elimination by terrorist groups.

The MYM argued that if criminals were now selecting victims based on ethnic identity, it created a frightening scenario in which travelling through certain roads in Plateau could become a matter of life and death based on a person’s ethnic identity.

The organisation added that allowing such ethnic targeting to continue unchecked would further deepen fear and suspicion among communities that have lived together for decades.

While the MYM said it did not want to pre-empt security investigations, it stressed that the timing and proximity of the recent killings in Mangu, following the specific threat against Berom and Mwaghavul people, demanded an urgent intelligence-led investigation to determine whether there was a pattern of ethnic targeting.

The group also urged Mwaghavul people to remain vigilant, strengthen early-warning systems, avoid night journeys through vulnerable routes and report suspicious movements, while warning against reprisal attacks or collective punishment of innocent people based on ethnicity or religion.

Continue Reading

Trending