Security credentials like usernames and passwords are a tempting target for hackers, and even the best password managers can come under threat from time to time. That was the case recently with the popular password manager 1Password, which recently disclosed (via Bleeping Computer) that its Okta support system was breached by malicious hackers.

Fortunately, it doesn’t appear that any customer data was stolen, so if you use 1Password, your login info should be safe for now. However, it’s always good to regularly update your passwords (or use passkeys) just in case they fall into the wrong hands.

In a blog post on its website, 1Password explained the situation. “We detected suspicious activity on our Okta instance related to their Support System incident,” 1Password said. “After a thorough investigation, we concluded that no 1Password user data was accessed.”

After detecting suspicious activity on September 29, 1Password “immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing.”

The link with Okta is interesting because it reveals a key vulnerability. Okta helps companies manage their users and ensure everyone can log in securely, and it also offers support for this process. As part of that, customers sometimes upload file archives to help diagnose problems, but these archives can contain sensitive data like session tokens and login data.

According to a detailed report from 1Password, a hacker stole a session cookie from a 1Password IT employee, then attempted to access the worker’s dashboard and request a list of admin users. Fortunately, the former action was blocked by Okta, while the second led to an automated email being sent to other 1Password admins, which alerted them to the breach.

While your login info is safe — no user data appears to have been accessed by the hacker — it shows just how easily seemingly secure systems can be breached by bad actors. In response to the incident, 1Password says it has reduced the number of “super admin” users, implemented tighter login rules for admins, and taken other measures.

Despite this episode, you should still pick one of the best password managers to keep your login data safe. After all, using an app to create and store unique passwords for you is far safer than using the same easily guessable login info for every account.

Related Posts

This extraordinary humanoid robot plays basketball like a pro, really

Digital Trends has already reported on the G1’s ability to move in a way that would make even the world’s top gymnasts envious, with various videos showing it engaged in combat, recovering from falls, and even doing the housework.

How to Use Pollo AI Video Generator: A Step-by-Step Guide

Here we’re talking about the Pollo AI video generator which can be used with a variety of prompts, and I’ll talk you through using each one.

This 49-inch curved Samsung ultrawide is down to $799.99 and basically replaces two monitors at once

You’re getting a massive 49-inch curved Dual QHD panel, 120Hz refresh rate, USB-C, HDR400, and an adjustable stand that’s built for serious productivity but still fast and smooth enough for after-hours gaming.