Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
1Password disclosed a security incident in 2023 involving an employee-facing Okta account, but the company said its investigation found no access to customer data. That is different from proving that 1Password has never had a breach: its January 2023 statement that it had “never had a breach” was the company’s claim at that time, not an independently verified finding covering every period or possible incident.
What does “hacked” mean in this case?
The word can describe several different events: an attack on a company’s internal systems, a takeover of an individual customer’s account, or access to encrypted vault data. Those outcomes are not interchangeable. The public record described here includes a 2023 incident in 1Password’s employee-facing identity-management environment; it does not establish that customer vaults were obtained or decrypted.
The available sources do not provide an independent, comprehensive register of every historical incident. So the careful answer is that 1Password reported an internal security incident, while saying that its investigation found no customer data was accessed. A universal claim that the service has never been hacked cannot be established from these sources.
What happened in the 2023 Okta incident?
In its October 23, 2023 incident report, 1Password said it detected suspicious activity on September 29 in its Okta instance, which it used to manage employee-facing applications. The company said an attacker accessed that Okta tenant with administrative privileges. It later attributed the activity to the breach of Okta’s Support System.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
1Password said its investigation found no evidence that the attacker accessed systems outside Okta and concluded, “no 1Password user data was accessed.” The company also said its Google instance was not affected. These are 1Password’s reported findings; the incident account is not independent verification of them. The report describes an incident, but not a compromise or decryption of customer vaults. Read 1Password’s incident update.
How does 1Password say it protects vault data?
1Password describes its vault protection as end-to-end encryption using two components: the account password a customer chooses and a machine-generated 128-bit Secret Key. The company says those are combined to protect vault data. Its support documentation names AES-GCM-256 authenticated encryption and PBKDF2-HMAC-SHA256 key derivation. It also describes Secure Remote Password (SRP) authentication, which is designed to authenticate a user without sending the account password over the internet.
Rank #2
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
These are descriptions of 1Password’s design, not a guarantee that every attack is harmless. Encryption can limit what an attacker can learn from encrypted vault data, but it does not by itself prevent account takeover, malware on an unlocked device, phishing outside the autofill flow, or exploitation of a software vulnerability. See 1Password’s security model documentation.
Device and phishing-related safeguards
1Password documents automatic locking, browser code-signature validation, and phishing protection that fills credentials only on saved sites. Its Watchtower feature alerts users to saved credential issues. The company says Watchtower checks those issues locally on the device and does not send users’ websites or passwords to 1Password or another party for that check. These features can reduce certain risks, but they do not replace a strong account password or safe device practices. 1Password’s Watchtower documentation.
Rank #3
What information can 1Password access?
End-to-end encryption does not mean the provider holds no information about an account. 1Password says vault items and metadata such as titles, URLs, tags, and custom icons are encrypted. Its privacy documentation also describes collecting account and operational information, including account type and ownership, payment details, usage information, IP address, connected devices, name, email address, and profile picture. The exact information associated with an account can therefore extend beyond encrypted vault contents. Read 1Password’s privacy policy.
The same policy says the company will promptly disclose breach-related risk and provide a transparent account of events. That is a stated disclosure commitment, not evidence that every future incident will be identified or reported in a particular way.
Rank #4
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
What do audits and certifications tell you?
1Password’s current audit page lists ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, and ISO 27701:2019 certifications, as well as SOC 2 Type 2. The company says annual penetration-test reports have been distributed through its Trust Center since November 3, 2025. It also says its public bug-bounty program moved to HackerOne in December 2024.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallThese are useful assurance signals, but certifications and security assessments have defined scopes and dates; they cannot prove that a company can never be compromised. The same audit page lists an Independent Security Evaluators penetration test and code review performed in April and June 2020. That dated assessment should not be treated as validation of every current system or feature. See 1Password’s audit and security information.
For context, 1Password’s security white paper landing page lists Release 0.5.2, dated March 5, 2026. A white paper explains a security design; it is not a substitute for reviewing the scope and date of an audit report. View the security white paper.
What should you do if you use 1Password?
The reported Okta incident does not, by itself, show that customer vaults were exposed. Practical account security still matters because a password manager can protect stored credentials only as well as the account and devices used to access it.
Quick Recap
- Use a unique, strong account password and keep your Secret Key available only through 1Password’s intended setup and recovery materials.
- Lock devices when unattended and keep their operating systems, browsers, and 1Password apps updated.
- Use Watchtower alerts to review weak, reused, or exposed credentials, and change affected passwords at the relevant services.
- Be cautious of unexpected sign-in requests or links. Autofill protection applies to saved sites; it is not a guarantee against every form of phishing.
- For a future incident, distinguish reports of internal-system access from evidence of customer-account access or vault-data exposure, and check the provider’s dated incident updates.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

