Connect with us

News

Password manager Dashlane says hackers stole some customers’ password vaults

info

Published

on

Password.jpg

Password manager maker Dashlane says hackers have obtained at least a dozen encrypted vaults used for storing customer passwords during a weekend cyberattack.

The company said on its website that hackers brute-forced the company’s two-factor authentication system, granting the hackers access to about 20 customer accounts. By defeating its two-factor mechanism, the hackers were able to download a copy of certain customers’ encrypted vaults, which store their passwords and other sensitive credentials.

Dashlane said on its incident page that there was no evidence of compromise of its own systems, but it has not yet said how the hackers were able to defeat its two-factor protections in order to access customer accounts. Two-factor is a security feature that protects accounts from being accessed with just a stolen username and password, typically by requiring an additional passcode to be sent to the phone of the account holder.

“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” said Dashlane. The company said that attackers can use automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires.”

The company said it has “taken steps to mitigate the risk of future incidents,” without saying what those were.

Dashlane said it has notified the 20 or so customers whose encrypted vaults were stolen. It’s not yet clear if the specific customers were targeted for a reason, such as because of who they are or what they do for a living.

Spokespeople for Dashlane did not respond to a request for comment. The company has not said if it knows who targeted its customers, or if the hackers contacted Dashlane with demands, such as a ransom.

The stolen vaults are scrambled and cannot be read without the customer’s master password, which is only known by the customer and is not uploaded to Dashlane in plaintext, the company’s website says. But Dashlane said that customers with an easily guessed master password may be at greater risk of having it guessed and their password vaults decrypted.

Data breaches affecting password manager companies are rare, but can have lasting consequences.

In 2022, LastPass confirmed that customer password vault backups were stolen during a cyberattack. While the vaults were protected with passwords only known to the customer, the password requirements for early customers were far weaker than the later standard, allowing hackers to brute-force and easily guess the passwords of some customers’ vaults. There have been several reports of hackers stealing vast amounts of customers’ crypto, likely by using private keys stored in stolen LastPass vaults that had their master passwords cracked following the breach.

A year earlier, Australian software house Click Studios warned all of its customers who use its flagship password manager, Passwordstate, to “reset all credentials” after hackers compromised its software update mechanism to plant malware on customer systems.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

I will end 2027 campaign if anyone proves I collected money in US – Peter Obi

info

Published

on

By

1788517007 Peter Obi.jpg

The Nigeria Democratic Congress, NDC, presidential candidate, Peter Obi, has given a condition for stopping his 2027 political campaign.

Obi vowed to stop his presidential campaign if anybody could provide evidence of him collecting money from Nigerians in the diaspora.

Speaking in the United States (US), Obi dismissed claims that he was in America to source funds for his presidential campaign.

He said:

Recommended

“People are saying that on my current trip to America, I have gone there to collect money from Nigerians in the diaspora.

“If anyone can show me one person in America who gave me even one dollar, I will end my 2027 campaign.

“I am using my own resources and paying all my bills, I am running around the world, trying to do the right thing.”

Continue Reading

News

Terrorists kill nine passengers in Plateau bus attack

info

Published

on

By

4E8AAAC4 C3E8 4C65 9CFD 94C52F5CE2CD.jpeg

Nine people have been killed after gunmen opened fire on a passenger bus at Dungus, Kuru District, Jos South council area.

The police command in Plateau confirmed the attack in a statement by its spokesman, Alfred Alabo, on Monday.

The command said it received a distress report at about 7:45 p.m. on Sunday that terrorists operating on a motorcycle had attacked the bus.

According to the statement, the Toyota bus, with registration number BUU 621 ZL, was conveying passengers to Jos when the gunmen opened fire.

It said seven people were confirmed dead at the scene, while two others who sustained gunshot injuries later died in hospital. The police said the development brought the total number of fatalities from the attack to nine.

The police commissioner, Ayodeji Faniyan, immediately mobilised Mobile Police operatives, tactical teams, homicide detectives and forensic experts to the scene.

(NAN)

Continue Reading

Trending