An active attack campaign is targeting users of the popular 1Password password manager, with the vendor’s security team warning that emails are being distributed claiming that account payment methods need updating.

There are two main takeaways from the official 1Password warning:

Do not respond to these; they are bogus and not from 1Password itself, no matter how realistic they might appear.

The campaign itself is speculative by nature and does not result from any breach of 1Password’s systems or servers.

The 1Password Attack Warning In Full

The attack campaign warning, posted to X by the official 1Password account on August 18, said:

“Our Security team has identified an active phishing campaign targeting 1Password users. The phishing emails claim your account's payment method needs to be updated and include a link to a fake ‘update payment method’ page.”

The use of payment update notifications is not a new social engineering tactic, but it has been deployed at a time when 1Password has not long ago changed its subscription rates , which could add fuel to the phishing fire by bringing urgency and believability to the table.

Unlike recent attacks against users of the LastPass password manager that employed lookalike domains in order to trick people into thinking that the phishing emails in question were genuine company communications, the criminals behind the 1Password campaign don’t appear to have bothered with such a deception. I have seen a few of the emails that have been sent to users, and the domains are entirely unconnected to either 1Password or its creators, AgileBits. 1Password has confirmed in its warning that it is “actively working with partners to take down the fraudulent domains.”

1Password also made it clear that “These emails are not from 1Password,” and the campaign itself “is not the result of any breach of 1Password's systems.” The latter is important to note, as there is often speculation surrounding any security issue when a password manager is concerned. 1Password advises recipients of fraudulent emails not to click any links and to forward the email itself to abuse@1password.com, where security teams can add the information to their investigations.