Getting started with 1Password for your growing team, or refining your setup? Our Secured Success quickstart guide is for you.
Forum Discussion
racerx_2502
7 months agoNew Contributor
Did 1Password get hacked? The Disney Employee said hackers got into his 1password account.
Hey Folks,
Decade+, happy 1password user here, however, my underpants clenched up when I read this on the WSJ today A Disney Worker Downloaded an AI Tool. It Led to a Hack That Ruined His Life. - W...
- 7 months ago
Hey everyone! I totally understand why this story raised concerns, but I'd like to assure you that 1Password was not hacked and remains secure.
In this particular case, the attacker compromised the individual’s local device. They intercepted his password using a keylogger, which allowed them to log into 1Password. Once a device is compromised, an attacker has nearly unrestricted access.
To help protect against attacks that target compromised devices, we recommend:
- Ensure device integrity — keep your devices free from malware by installing security updates, enabling built-in security features, and using endpoint protection tools that actively detect and prevent threats.
- Trust only verified sources — download software exclusively from trusted providers. Avoid unverified applications that could contain hidden malware.
- Strengthen authentication for critical accounts —use phishing-resistant authentication methods like hardware security keys (e.g., YubiKey) or a separate authenticator app to reduce the risk of credential compromise.
- Limit exposure from browser extensions — review and disable unnecessary or untrusted extensions, as they can introduce vulnerabilities that attackers may exploit.
For more details on how 1Password protects information on your devices (and when it can’t), I would recommend reading our blog linked below. 👇
🔗 How 1Password protects information on your devices (and when it can’t)
prime
7 months agoDedicated Contributor
Correct, once a hacker has access to your computer, it’s game over. Nothing, even 1Password, can save you.
1Password wasn’t hacked.
wab
7 months agoNew Contributor
I agree with prime. Where 2FA helps you in this scenario is not with preventing 1PW access, it's with preventing access to your other sites (provided you have 2FA activated on those sites). That's why you shouldn't use 1PW to provide the second factor. It is also why you should not have your authenticator app (like authy) accessible on the same computer.
- racerx_25027 months agoNew Contributor
I'm using a lot of passkeys these days which doesn't require a second device. 1password just dishes them out via browser pop up . Easy peasy. Makes me wonder if that's not a good thing