Connect with us

Tech

Password manager Dashlane says hackers stole some customers’ password vaults

Password manager maker Dashlane says hackers have obtained at least a dozen encrypted vaults used for storing customer passwords during a weekend cyberattack.

The company said on its website that hackers brute-forced the company’s two-factor authentication system, granting the hackers access to about 20 customer accounts. By defeating its two-factor mechanism, the hackers were able to download a copy of certain customers’ encrypted vaults, which store their passwords and other sensitive credentials.

Dashlane said on its incident page that there was no evidence of compromise of its own systems, but it has not yet said how the hackers were able to defeat its two-factor protections in order to access customer accounts. Two-factor is a security feature that protects accounts from being accessed with just a stolen username and password, typically by requiring an additional passcode to be sent to the phone of the account holder.

“The goal of the attack was to brute-force two-factor authentication (2FA) protections to allow the attacker to register new devices on existing user accounts,” said Dashlane. The company said that attackers can use automated software to “rapidly submit every possible numeric combination to the system, hoping to guess the exact sequence before the short-lived [two-factor] security code expires.”

The company said it has “taken steps to mitigate the risk of future incidents,” without saying what those were.

Dashlane said it has notified the 20 or so customers whose encrypted vaults were stolen. It’s not yet clear if the specific customers were targeted for a reason, such as because of who they are or what they do for a living.

Spokespeople for Dashlane did not respond to a request for comment. The company has not said if it knows who targeted its customers, or if the hackers contacted Dashlane with demands, such as a ransom.

The stolen vaults are scrambled and cannot be read without the customer’s master password, which is only known by the customer and is not uploaded to Dashlane in plaintext, the company’s website says. But Dashlane said that customers with an easily guessed master password may be at greater risk of having it guessed and their password vaults decrypted.

Data breaches affecting password manager companies are rare but can have lasting consequences.

In 2022, LastPass confirmed that customer password vault backups were stolen during a cyberattack. While the vaults were protected with passwords only known to the customer, the password requirements for early customers were far weaker than the later standard, allowing hackers to brute-force and easily guess the passwords of some customers’ vaults. There have been several reports of hackers stealing vast amounts of customers’ crypto, likely by using private keys stored in stolen LastPass vaults that had their master passwords cracked following the breach.

A year earlier, Australian software house Click Studios warned all of its customers who use its flagship password manager, Passwordstate, to “reset all credentials” after hackers compromised its software update mechanism to plant malware on customer systems.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Passionfroot raises $15M to expand its B2B creator marketplace to the US

Passionfroot, a German startup building a marketplace connecting B2B creators with brands, said on Wednesday it has raised $15 million in a Series A funding round led by Insight Partners.

Rebecca Liu-Doyle, managing director at Insight Partners, said Passionfroot is placed well at a time when creators are specializing as AI companies look for more visibility.

“Passionfroot has the perfect dynamics on both sides to warrant a true marketplace for B2B creators. On the demand side, there is increasing consumerization of the way B2B brands go to market. That’s a product of, in part, AI technology requiring evangelism, narrative building, and education. On the supply side, there are people who have real expertise, understand a market deeply, and want to create quality content,” she told TechCrunch over a call.

With the funding, the Berlin-based startup’s co-founder and CEO, Jen Phan, is moving to New York, where Passionfroot is opening an office to expand its U.S. operations. The company is also opening an office in São Paulo, and expanding its current headcount of 15 employees.

As AI makes it easier to build products, companies are focusing on using creators to improve brand recall and recognition, Phan said.

“Every head of marketing or growth leader I’m talking to is saying really the same thing: AI is commoditizing software and flooding every category with new products, features, and launches. It’s incredibly crowded and noisy. That is why B2B buyers are going to channels like LinkedIn, a creator’s Substack, or a podcast on YouTube to discover new products and tools,” she said.

Phan said over the last year, the company increased its revenue by 13 times, and onboarded clients such as ElevenLabs, Figma, Replit, Framer, and Gamma.

Since its last fundraise in 2024, the company has released an AI agent called Zest, which helps brands create, execute and monitor the performance of campaigns. Passionfruit claims Zest can also help companies find suitable creators both inside and outside the platform that are suited to its marketing strategy.

The startup says it uses a proprietary creator graph based on data about reach and performance from thousands of campaigns. There’s also a wallet that companies can use to pay creators across the globe, and measure their expenditure.

Passionfroot claims it has paid at least $10 million to creators on its platform in the last 18 months.

The company says it is working on helping its clients measure how a campaign is impacting AI citations, and how their brand appears in AI-powered answers. The startup is also planning to build AI features for creators, such as helping them with monetization tips and content ideas.

The funding comes as creator platforms like Substack and Beehiiv move to help creators find better monetization opportunities. Beehiiv launched a new community and ad marketplace last week, and Substack has introduced subscriber-only perks within newsletters.

Passionfroot’s Series A also saw participation from existing investors Creandum, Supernode Global, and s16vc. The company has raised more than $21 million so far.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

Cascade raises $3.5M to help construction firms find and win projects

Cascade, a startup building a platform to help architecture, engineering, and construction firms find and win projects, has raised a $3.5 million seed round from Andreessen Horowitz Speedrun, Ada Ventures, and Snowball VC.

Launched in 2025, Cascade is a result of its founders, Hannia Zia and Joana Ferreira, witnessing firsthand the difficulty construction businesses face with predictably securing work.

“My mother worked in a company that sold materials to construction companies, and my uncle built mansions in the Middle East. They’re incredible at their craft but just don’t have access to the right tools to get more work,” Ferreira told TechCrunch. And Zia recalled the time her father tried starting a construction business back in her native Pakistan: “He just couldn’t get enough projects to sustain himself.”

Zia describes the current process of finding construction projects as a “constant treasure hunt,” with firms having to log into each U.S. state, city, district, county, and federal agency’s portals. “So if you’re really good at building suspension bridges, you have to find all of those opportunities across these disparate portals.” 

Cascade aims to help architecture, construction, and engineering firms on this front by tracking ongoing and upcoming projects, and then using prior tender data to predict which developers are likely to win the deals.

Here’s how the platform works: A company signs up to the platform, and then Cascade uses AI tools to determine which projects they have the best chance of winning. It also predicts what projects are coming up, using different signals and data points across U.S. states, local districts, private contracts, and federal agencies. For example, if a state announces a $100 million affordable housing grant, Cascade will monitor which developers won the grant the last time it was announced. 

“We connect that data, and we tell our customers: ‘Most likely one of these five developers will win this newly announced grant, so go start talking to them to win projects,’” Ferreira explained.

The duo applied to a16z’s Speedrun last September. They said the pressure to do well on demo day and being around the “brilliance” of other founders helped the company sign contracts with firms that have built the JFK and La Guardia airports, Four Seasons hotels, and some data centers. “Speedrun gave us visibility and a stamp of approval to close big deals,” Zia said.

The startup will use the fresh cash to go to market, host industry events, and hire more engineers. 

Other startups in this area include GovWin IQ and ConstructConnect, but Ferreira argues Cascade is a bit more AI-native than these platforms.

“Every time a customer wins a bid, they give feedback, so the system keeps getting smarter. Over time, we’ll have a complete map of the industry that our AI can traverse to predict the best projects and leads for each customer,” she said.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading

Tech

If you pay a hacker’s ransom, chances are that they’ll come back for more

Governments have long warned not to pay a hacker’s ransom demands, arguing that doing so only lets criminals profit from their cyberattacks and funds the next one. There’s also another reason: The hackers are unlikely to leave you alone if you pay up once, and many will come back demanding more.

In a report published Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and found that over one-third of companies that paid a hacker’s ransom were hit with a second extortion demand. The findings underscore the long-held understanding among security researchers and network defenders that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away.

Proofpoint’s data shows that ransomware attacks and extortion attacks have evolved from a single transaction where hackers would get paid once and move on, into an effort using multiple forms of leverage, such as retaining stolen data under the threat of publicly releasing it.

While hackers have claimed in the past that they will delete or destroy the victim’s stolen data, past incidents have shown that not to be the case.

Last month, a hack at market research firm Klue exposed data belonging to its customers, including several cybersecurity firms. The company said it struck a deal with the hackers, who claimed to have deleted the data, but the company later conceded that a separate hacking group swiped a sample of the company’s stolen data, leaving its customers exposed to potential future extortion demands.

A similar situation befell Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the health and medical data of the majority of people in America, some 192 million people. Amid a dispute between the hackers and their affiliates (criminal groups often subcontract out attacks), Change Healthcare paid separate ransoms to both groups of criminals to keep the sensitive medical data off of the internet.

Security researchers have long suspected that ransomware gangs and extortion rackets will keep hold of the victim’s stolen data, even after a payment is made. U.K. law enforcement confirmed this during their takedown efforts targeting the prolific LockBit ransomware gang in 2024. Police said that they found victims’ stolen data stored on LockBit’s servers long after they had paid the ransom.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

source

Continue Reading