logo

Phishers target 1Password users with convincing fake breach alert

ID: 62d908d0-27cb-5c92-8ef3-672a3eeeda5d

STIX ID: report--62d908d0-27cb-5c92-8ef3-672a3eeeda5d

Feed Name: Malwarebytes Blog

Threat Score
55/100

Date Published: 2025-10-06

Date Updated: 2026-04-28

...
...

Malwarebytes observed a targeted phishing campaign impersonating 1Password's Watchtower feature to steal password vault credentials. The phishing email originated from [email protected] and linked to the phishing domain onepass-word.com (routed via mandrillapp); vendors quickly classified the domain as malicious. The report highlights red flags, provides IOCs, and advises users to avoid clicking unsolicited links and to verify account status via the official 1Password site or app.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.