Skip to main content
1PasswordSecurity incident

1Password Issues New Payment Update Warning As Scammers Strike

What happened

An active phishing campaign is targeting users of 1Password, with fraudulent emails claiming that account payment methods need updating.

Source

forbes.comAug 18, 2026By Davey Winder, Senior Contributor

1Password Issues New Payment Update Warning As Scammers Strike

Article excerpt

Highlighted: the sentence this signal was extracted from

By Davey Winder, Senior Contributor. An active attack campaign is targeting users of the popular 1Password password manager, with the vendor's security team warning that emails are being distributed claiming that account payment methods need updating. There are two main takeaways from the official 1Password warning: Do not respond to these; they are bogus and not from 1Password itself, no matter how realistic they might appear. The campaign itself is speculative by nature and does not result from any breach of 1Password's systems or servers. The attack campaign warning, posted to X by the official 1Password account on August 18, said: "Our Security team has identified an active phishing campaign targeting 1Password users. The phishing emails claim your account's payment method needs to be updated and include a link to a fake 'update payment method' page." The use of payment update notifications is not a new social engineering tactic, but it has been deployed at a time when 1Password has not long ago changed its subscription rates, which could add fuel to the phishing fire by bringing urgency and believability to the table. Unlike recent attacks against users of the LastPass password manager that employed lookalike domains in order to trick people into thinking that the phishing emails in question were genuine company communications, the criminals behind the 1Password...

Keep reading with a free account

The rest of this article, and every signal for 1Password, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
Active phishing campaign targeting users with fake payment update emails

Extraction

Confidence
90%
Detected
Aug 18, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for 1Password and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at 1Password this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/01c009f1-4cb3-f107-e920-813eadb7fe38 returns this record as JSON. POST /v1/companies/enrich returns every signal for 1password.com.

{
  "signal_id": "01c009f1-4cb3-f107-e920-813eadb7fe38",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-08-18T11:23:57+00:00",
  "company": {
    "name": "1Password",
    "domain": "1password.com"
  },
  "data": {
    "url": "https://www.forbes.com/sites/daveywinder/2026/08/18/1password-issues-new-payment-update-warning-as-scammers-strike/",
    "title": "1Password Issues New Payment Update Warning As Scammers Strike",
    "author": "Davey Winder, Senior Contributor",
    "excerpt": "By Davey Winder , Senior Contributor. An active attack campaign is targeting users of the popular 1Password password manager, with the vendor’s security team warning that emails are being distributed claiming that account payment methods need updating. There are two main takeaways from the official 1Password warning: Do not respond to these; they are bogus and not from 1Password itself, no matter how realistic they might appear. The campaign itself is speculative by nature and does not result from any breach of 1Password’s systems or servers. The attack campaign warning, posted to X by the official 1Password account on August 18, said: “Our Security team has identified an active phishing campaign targeting 1Password users. The phishing emails claim your account's payment method needs to be updated and include a link to a fake ‘update payment method’ page.” The use of payment update notifications is not a new social engineering tactic, but it has been deployed at a time when 1Password has not long ago changed its subscription rates , which could add fuel to the phishing fire by bringing urgency and believability to the table. Unlike recent attacks against users of the LastPass password manager that employed lookalike domains in order to trick people into thinking that the phishing emails in question were genuine company communications, the criminals behind the 1Password...",
    "summary": "An active phishing campaign is targeting users of 1Password, with fraudulent emails claiming that account payment methods need updating.",
    "planning": false,
    "image_url": "https://imageio.forbes.com/specials-images/imageserve/69edfccc8f76fcd98e09ad00/0x0.jpg?format=jpg&height=900&width=1600&fit=bounds",
    "confidence": 0.9,
    "published_at": "2026-08-18T11:23:57Z",
    "vulnerability": "Active phishing campaign targeting users with fake payment update emails",
    "article_sentence": "An active attack campaign is targeting users of the popular 1Password password manager, with the vendor’s security team warning that emails are being distributed claiming that account payment methods need updating."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.