Dashlane

Dashlane

Password management with Autofill and SSO

Overview

Dashlane provides password management for individuals and organizations, helping users keep credentials safe and easy to use. It stores passwords securely, autofills login forms, and offers Single Sign-On (SSO) so users can log into many sites or apps with one set of credentials. The product works via a browser and mobile apps, with unlimited password storage, secure sharing, and priority support through a subscription model. Dashlane stands out from competitors with its user-friendly interface, strong customer support, and features like seamless autofill, secure sharing, and enterprise onboarding, which together make security simpler rather than a complicated task. Its goal is to simplify security for both individuals and organizations, making it easy to protect and manage online credentials.

About Dashlane

Simplify's Rating
Why Dashlane is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Consumer Software

Enterprise Software

Cybersecurity

Company Size

201-500

Company Stage

Series D

Total Funding

$213.3M

Headquarters

New York City, New York

Founded

2009

Get referred to Dashlane

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • KnowBe4 integration shipped April 6, 2026, turning risky logins into immediate training.
  • Microsoft Sentinel threat-intelligence delivery on May 19, 2026 expands Dashlane's enterprise security stack.
  • Dashlane reported 25,000 organizations and millions of consumers, supporting cross-sell momentum.

What critics are saying

  • The May 31, 2026 brute-force attack suspended accounts and exposed encrypted vaults for under 20 users.
  • Dashlane's one-third weak-login finding proves password sprawl still undermines its enterprise promise.
  • If passwordless and Omnix adoption stalls, 25,000 customers can defect to 1Password or Microsoft.

What makes Dashlane unique

  • Dashlane's May 2026 Omnix platform extends credential security beyond vaults into browsers.
  • Yubico and Dashlane launched passwordless, phishing-resistant vault login in May 2026.
  • Dashlane's June 2026 AI Advisor beta brings natural-language credential security to admins.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$213.3M

Above

Industry Average

Funded Over

8 Rounds

Notable Investors:
Series D funding is typically for companies that are already well-established but need more funding to continue their growth. This round is often used to stabilize the company or prepare for an IPO.
Series D Funding Comparison
Above Average

Industry standards

$77M
$70M
Twilio
$80M
Handshake
$100M
Affirm
$110M
Dashlane

Benefits

Hybrid Work Options

Relocation Assistance

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

-2%
Android Headlines
Jun 3rd, 2026
Hackers stole Dashlane password vaults without ever breaching Dashlane itself.

Hackers stole Dashlane password vaults without ever breaching Dashlane itself. Jun 3, 2026 Dashlane has disclosed a security incident in which attackers reportedly brute-forced its two-factor authentication system, gaining access to around 20 customer accounts and downloading at least a dozen encrypted password vaults. The company says there is no evidence that its core systems were compromised and that affected customers have been notified. Dashlane, a password manager company, has confirmed a breach of security. The company says that hackers managed to steal some customers' password vaults. It's not what you think, though, as Dashlane itself was not breached. 20 password vaults were stolen in the process. So, what exactly happened? Dashlane says that hackers managed to get at least a dozen encrypted vaults used for storing customer passwords during a weekend cyberattack. Dashlane said that hackers brute-forced the company's two-factor authentication system. That granted them access to about 20 customer accounts. They were able to download a copy of certain customers' encrypted vaults, which store passwords and other sensitive credentials. The company added that there is no evidence of compromise of its own systems. "The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts," said the company. Dashlane added that attackers can use automated software to "rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires." Dashlane also confirmed that it has "taken steps to mitigate the risk of future incidents," but it did not share any details regarding that. So we don't know exactly what those steps are. The company also confirmed that it notified the customers whose encrypted vaults were stolen. It is still unclear whether those customers were targeted by hackers, or was that pure coincidence. The company does say that the stolen vaults are scrambled, as a master password is needed. Dashlane did note that the stolen vaults are scrambled and cannot be read without the customer's master password. That password is only known by the customer and is not uploaded to Dashlane in plain text. As a reminder, back in 2022, LastPass confirmed that its customer password vault backups were stolen. That was considerably different, though, as that was an actual breach into LastPass.

FundNaija
Jun 3rd, 2026
Is your startup's security ironclad? Lessons from the Dashlane breach.

Is your startup's security ironclad? Lessons from the Dashlane breach. The security wake-up call every founder needs. For many African entrepreneurs, cybersecurity often falls to the bottom of the priority list, overshadowed by pressing needs like securing seed funding or scaling operations. However, a recent security incident involving the password manager giant Dashlane proves that no company - no matter how large - is immune to sophisticated cyberattacks. Dashlane recently disclosed that hackers successfully bypassed their two-factor authentication (2FA) systems through "brute-force" attacks. This allowed unauthorized parties to gain access to customer accounts and download sensitive password vaults. For a startup founder, this isn't just a tech headline; it's a business continuity crisis. Why this matters for founders. As you build your business, you are likely handling sensitive data, including customer records, financial information, and proprietary IP. A data breach doesn't just put your data at risk; it threatens the trust you have worked so hard to build with your investors and users. * Investor Due Diligence: When you apply for funding via platforms like FundNaija, investors look at your risk profile. A history of poor data security can be a massive red flag that stalls a funding round. * Trust is Currency: For fintech and e-commerce startups in Africa, customer trust is your greatest competitive advantage. A breach can lead to immediate churn and long-term reputational damage. * Beyond 2FA: The Dashlane incident reminds FundNaija, Inc. that 2FA is a starting point, not a complete solution. Founders should implement hardware security keys, regular internal audits, and strict access controls for team members. Protecting your venture. At FundNaija, FundNaija, Inc. see thousands of startups at various stages of growth. The ones that succeed aren't just the ones with the best product; they are the ones with the most resilient foundations. Cybersecurity is an investment in your company's valuation, not just an IT expense. Start by auditing the tools your team uses. Ensure that your password management policies are enforced, transition to multi-layered authentication, and keep your software stack updated. Remember, as your business grows, so does your target profile for cyber-threats. Don't let a preventable security lapse be the reason your startup fails to scale. Prioritize your digital hygiene today so you can focus on what really matters: building, selling, and growing your business. Want to check your funding readiness? Try FundNaija's free FundScore. Get funding-ready today. Create an AI-powered business plan and discover funding opportunities tailored to your business.

IT Security News
Jun 2nd, 2026
Dashlane discloses brute-force attack, encrypted vaults of fewer than 20 users downloaded.

Dashlane discloses brute-force attack, encrypted vaults of fewer than 20 users downloaded. 2026-06-02 07:06 Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026, the company said an "external" threat actor launched a brute-force attack against certain Dashlane user accounts with the aim of breaking two-factor authentication (2FA) Hacking & Cracking Read the original article: Password manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. "Your account has been temporarily suspended for security reasons as someone... Antivirus & Malware June 1, 2026 Engineers' weekends ruined as Dashlane's automatic protections kicked in This article has been indexed from www.theregister.com - ArticlesRead the original article: Password manager Dashlane suspends customer accounts amid brute-force attacks June 1, 2026 Dashlane launched Credential Risk Detection, a solution that continuously monitors and detects at-risk credential activity in real-time across the workforce, whether employees use a password manager or not. The web extension-based solution is the latest Dashlane innovation that shifts credential security from passive defense to proactive protection, enabling enterprises to... October 8, 2024

Tech247news
Jun 2nd, 2026
Dashlane exposes brute force attack, encrypted vault downloaded by less than 20 users.

Dashlane exposes brute force attack, encrypted vault downloaded by less than 20 users. Ravi LakshmananJune 2, 2026Identity security/data protection Password manager Dashlane has revealed that fewer than 20 users of its personal subscription plans had their encrypted vaults downloaded following a brute force attack by an unknown party. On May 31, 2026, the company announced that an "external" attacker launched a brute force attack against certain Dashlane user accounts in an attempt to defeat two-factor authentication (2FA) protections and allow new devices to be registered to existing user accounts. It's unclear exactly how many users were targeted, but Dashlane said the high volume of attempts against these accounts resulted in account suspensions and authentication issues through built-in security controls. Access to the account has since been restored, but the company said the attackers were successful in a small number of cases and were able to download copies of encrypted vaults owned by fewer than 20 individual plan users. "We have notified each of these users directly." "If you are a Dashlane user and have not yet received a message from Dashlane regarding Vault risk, your Dashlane account will not be affected." Please note that you cannot access your vault data without your master password. Unless this password is simple and predictable, attempts to break into the safe are unlikely to be successful. Dashlane also noted that its internal systems were not affected by this incident. As a precaution, users are encouraged to review the devices registered to their accounts, remove any devices they don't recognize, enable 2FA, and use a strong master password that is "long, unique, and difficult to guess."

DanSec
Jun 2nd, 2026
Cybersecurity brief - 2026-06-02.

Cybersecurity brief - 2026-06-02. 2026-06-02 Major Incidents or Breaches * Dashlane, a password manager, disclosed a brute-force attack resulting in the download of encrypted vaults for fewer than 20 personal users. Affected accounts were automatically locked to prevent further compromise. Users also reported account lockouts due to login attempts from unfamiliar locations and devices [[3]] [[12]] [[30]]. * Over 30 npm packages under Red Hat's @redhat-cloud-services namespace were compromised in a supply chain attack dubbed "Miasma," distributing a variant of the Shai-Hulud malware to steal developer credentials and secrets [[4]] [[10]]. * A malicious supply chain campaign targeted developers using OpenAI Codex via a fraudulent npm package, codexui-android, which was designed to steal authentication tokens [[8]]. * Dutch police dismantled a botnet comprising 17 million devices that was used as a residential proxy network and facilitated various cybercrimes [[33]]. * Nearly 2,000 WordPress websites were infected with malware that uses Steam Community profile comments to hide command-and-control data [[13]]. * A fake BlueWallet application targeting Mac users was observed stealing passwords, crypto wallet information, and clipboard data [[40]]. * Threat actor DriveSurge hijacked thousands of websites to distribute malware via ClickFix and FakeUpdate campaigns [[9]]. * The Spanish National Police arrested an individual responsible for leaking sensitive data of government employees, including those from the National Cybersecurity Institute (INCIBE) [[11]]. * The Instagram accounts of high-profile individuals and organisations were compromised via Meta's AI support bot, allowing attackers to seize and deface accounts with pro-Iranian content [[27]]. Newly Discovered Vulnerabilities * A critical Windows Netlogon remote code execution vulnerability (CVE-2026-41089) is now being actively exploited. Organisations are urged to patch immediately [[16]] [[34]]. * A new Linux kernel vulnerability, known as CIFSwitch and present for 19 years, allows low-privileged users to escalate to root. Proof-of-concept exploit code has been released [[5]] [[37]]. * A vulnerability in the WP Maps Pro WordPress plugin (CVE-2026-8732) is being exploited to allow unauthenticated attackers to create administrative accounts on affected sites [[32]]. * Palo Alto Networks PAN-OS authentication bypass vulnerability (CVE-2026-0257) has been under active exploitation since four days after its public disclosure, with at least two observed attack waves [[5]] [[22]] [[38]]. Notable Threat Actor Activity * China-aligned threat groups launched Operation Dragon Weave, targeting officials and citizens in the Czech Republic and Taiwan with the AdaptixC2 agent for cyber espionage [[6]]. * Recent campaigns have seen attackers leveraging SVG files in phishing emails, bypassing traditional detection methods [[28]]. * Carnival Corporation, a major cruise line operator, was named among top targets in recent cyber incidents [[39]]. Trends, Tools, or Tactics of Interest * Attack vectors in containerised environments remain focused on exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks [[1]]. * Malware campaigns are increasingly using unconventional channels for command-and-control, such as hiding payloads in Steam Community profiles [[13]]. * There is a trend towards faster exploitation of vulnerabilities following public disclosure, underscoring the importance of rapid patch management [[15]] [[38]]. * A new browser-based technique, FROST, enables websites to infer user activity on SSDs using JavaScript, raising concerns over novel tracking vectors [[26]]. * MSPs are moving beyond traditional vCISO tools, seeking integrated security growth platforms for broader service delivery [[7]]. Regulatory or Policy Developments Affecting the Security Industry * Anthropic will open its Mythos AI system to the EU's ENISA as part of Project Glasswing, reflecting deepening cooperation between the European Commission and AI vendors [[20]]. * Microsoft's legal threats against researchers disclosing zero-day exploits have sparked backlash, raising concerns about the chilling effect on vulnerability research [[21]]. * Oracle has shifted to a monthly patch cadence, with its first rollout addressing 77 vulnerabilities [[31]].

Recently Posted Jobs

Sign up to get curated job recommendations

Dashlane is Hiring for 8 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →