{"id":20398,"date":"2025-10-06T14:38:52","date_gmt":"2025-10-06T14:38:52","guid":{"rendered":"http:\/\/localhost\/?p=20398"},"modified":"2025-10-06T14:38:52","modified_gmt":"2025-10-06T14:38:52","slug":"phishers-target-1password-users-with-convincing-fake-breach-alert","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=20398","title":{"rendered":"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-06T18:40:29&#8243;,&#8221;description&#8221;:&#8221;In a very recent and well-targeted phishing attempt, scammers tried to get hold of the 1Password credentials belonging to a Malwarebytes\u2019 employee.\\n\\nStealing someone\u2019s 1Password login would be like hitting the jackpot for cybercriminals, because they potentially export all the saved logins the target stored in the password manager.\\n\\nThe phishing email looked like this:\\n\\n![email screenshot 1Password](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/10\/email_screenshot.png)\\n\\n\\u003e \u201cYour 1Password account has been compromised\\n\\u003e \\n\\u003e Unfortunately, Watchtower has detected that your 1Password account password has been found in a data breach. This password protects access to your entire vault.\\n\\u003e \\n\\u003e Take action immediately\\n\\u003e \\n\\u003e To keep your account secure, please take the following actions:\\n\\u003e \\n\\u003e &#8211; Change your 1Password account password\\n\\u003e \\n\\u003e &#8211; Enable two-factor authentication\\n\\u003e \\n\\u003e &#8211; Review your account activity\\n\\u003e \\n\\u003e Secure my account now\\n\\u003e \\n\\u003e If you need help securing your account, or have any questions, contact us. Our team is on hand to provide expert, one-on-one support.\u201d\\n\\nWhile the email looks convincing enough, you can spot a few red flags.\\n\\n  * The sender&#8217;s address `watchtower@eightninety[.]com` does not belong to 1Password, which typically use the domain` @1password.com`.\\n  * If you hover over the \u201cSecure my account now\u201d button you\u2019ll notice that it points to: `https:\/\/mandrillapp[.]com\/track\/click\/30140187\/onepass-word[.]com?p={long-identifier}`\\n\\n\\n\\nAlthough 1Password&#8217;s Watchtower feature can send alerts about compromised passwords, it does so by checking its database of known data breaches and then notifying you directly within the 1Password app or through very specific emails about the breach\u2014not by sending a generic message like this.\\n\\nObviously, the `onepass-word[.]com` is a feeble attempt to make it look legitimate. I guess all the good typosquats were already taken or protected. What&#8217;s interesting is that the \u201cContact us\u201d link goes to the legitimate `support.1password.com`, although it also flows through a redirect through mandrillapp.\\n\\nMandrillapp is a transactional email API and delivery service provided by Mailchimp. It enables organizations to send automated, event-driven emails like order confirmations, password resets, and shipping notifications. Mandrill also provides delivery tracking and statistics to their customers.\\n\\nWhat the scammers may not have realized is that Mandrillapp doesn&#8217;t forward people to known phishing websites.\\n\\n![Malwarebytes blocks onepas-word.com](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/10\/one-passwordcomblock.png)\\n\\nShortly after the emails went out on October 2, the domain was already classified as a phishing site by several vendors. By October 3, anyone that clicked the button would end up viewing an error message on `mandrillapp[.]com` saying `bad url &#8211; reference number: {23 character string}`.\\n\\nBut early birds would have seen this form:\\n\\n![online form asking for 1password credentials](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/10\/credentials-form.png)\\n\\nAnyone who fell for this scam would have sent their 1Password credentials straight to the phishing crew.\\n\\nOn September 25, 2025, Hoax-Slayer reported about a very similar phishing expedition. This might indicate that this was the first\u2014and probably is not the last\u2014attempt, so be warned.\\n\\nWith the key to your password vault, cybercriminals could take over all your important accounts and potentially steal your identity, so be very careful about where and when you use these credentials.\\n\\n## **Our advice:**\\n\\n  * **Do not** click any links or buttons in an unsolicited email\\n  * **Do not** provide any of your 1Password credentials or personal information.\\n  * If you are concerned about your 1Password account, go directly to the official 1Password website or app and check your account status there.\\n  * Use up-to-date real-time protection which includes a web protection module.\\n\\n\\n\\n## Indicators of compromise (IOCs)\\n\\nEmail address:\\n\\n`watchtower@eightninety[.]com`\\n\\nDomain Phishing website:\\n\\n`onepass-word[.]com`\\n\\n* * *\\n\\n**We don &#8216;t just report on threats &#8211; we help safeguard your entire digital identity**\\n\\nCybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using identity protection.&#8221;,&#8221;published&#8221;:&#8221;2025-10-06T17:24:42&#8243;,&#8221;modified&#8221;:&#8221;2025-10-06T17:24:42&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Phishers target 1Password users with convincing fake breach alert&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A&#8221;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2025\/10\/phishers-target-1password-users-with-convincing-fake-breach-alert&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-06T18:40:29&#8243;,&#8221;description&#8221;:&#8221;In a very recent and well-targeted phishing attempt, scammers tried to get hold of the 1Password credentials belonging to a Malwarebytes\u2019 employee.\\n\\nStealing someone\u2019s 1Password login&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-20398","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=20398\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-10-06T18:40:29&#8243;,&#8221;description&#8221;:&#8221;In a very recent and well-targeted phishing attempt, scammers tried to get hold of the 1Password credentials belonging to a Malwarebytes\u2019 employee.nnStealing someone\u2019s 1Password login...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=20398\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-06T14:38:52+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20398#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20398\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A\",\"datePublished\":\"2025-10-06T14:38:52+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20398\"},\"wordCount\":849,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20398#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20398\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20398\",\"name\":\"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-10-06T14:38:52+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20398#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=20398\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=20398#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=20398","og_locale":"en_US","og_type":"article","og_title":"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-10-06T18:40:29&#8243;,&#8221;description&#8221;:&#8221;In a very recent and well-targeted phishing attempt, scammers tried to get hold of the 1Password credentials belonging to a Malwarebytes\u2019 employee.nnStealing someone\u2019s 1Password login...","og_url":"https:\/\/zero.redgem.net\/?p=20398","og_site_name":"zero redgem","article_published_time":"2025-10-06T14:38:52+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=20398#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=20398"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A","datePublished":"2025-10-06T14:38:52+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=20398"},"wordCount":849,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=20398#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=20398","url":"https:\/\/zero.redgem.net\/?p=20398","name":"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-10-06T14:38:52+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=20398#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=20398"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=20398#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Phishers target 1Password users with convincing fake breach alert_MALWAREBYTES:979DD33A430ADD4884BB57A667FD209A"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20398","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=20398"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/20398\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=20398"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=20398"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=20398"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}