1Password is warning its users about an active phishing campaign in which attackers are sending fraudulent emails claiming that account payment information needs to be updated. The messages direct recipients to fake payment-update pages designed to make the emails appear like legitimate 1Password communications.
The company’s security team identified the campaign and issued a warning on August 18 through 1Password’s official X account. The company said the emails falsely claim that a user’s payment method requires an update and contain links leading to fraudulent pages.
1Password emphasized that the messages are not genuine and should not be answered or acted upon, regardless of how convincing they may appear. Users who receive the emails are advised not to click any included links and instead forward the messages to abuse@1password.com so the company’s security team can use the information in its investigation.
The phishing campaign comes after 1Password recently increased the prices of some subscription plans, a change that could make payment-related emails appear more believable to recipients. Payment-update messages are a longstanding social-engineering tactic used by scammers to create a sense of urgency around account or billing issues.
The campaign also differs from recent attacks targeting LastPass users, in which attackers used domains designed to resemble legitimate company websites. In the 1Password campaign, the fraudulent emails reviewed in the report used domains that were not connected to 1Password or its parent company, AgileBits.
1Password said it is working with partners to remove the fraudulent domains associated with the campaign. The company also stressed that the phishing activity did not result from a breach of its own systems.
The warning is particularly significant because security incidents involving password managers can prompt speculation about whether the companies themselves have been compromised. In this case, 1Password has explicitly stated that there is no connection between the phishing campaign and a breach of its systems.
Leave a comment