Skip to main content
1P_Timothy
Community Manager
July 14, 2026

Recent phishing emails impersonating a third-party identity provider

  • July 14, 2026
  • 1 reply
  • 20 views

Our Security team has identified an active phishing campaign targeting 1Password users. The phishing emails impersonate a third-party identity provider breach notification and include a malicious link.

These emails are not from 1Password. This campaign is not the result of any breach of 1Password's systems, and we're actively working with partners to take down the fraudulent domains.

If you've received one of these emails:

For guidance on spotting and handling phishing: 1password.community/kb/cybersecurity-glossary/phishing/156555

1 reply

Calion
July 15, 2026

Holy crap that was sophisticated. I was wholly taken in by the email. Fortunately the domain has been taken down, so I wasn’t given the opportunity to give them any personal info (which I may or may not have done).

1P_Timothy
Community Manager
July 15, 2026

Thanks for sharing this ​@Calion. It can be so easy to miss the increasingly smaller red flags in phishing emails when you’re clicking through your inbox. The section on validating emails from 1Password in our guide might be of interest.