1Password firewall rules changed
Description
AlphaSOC detected a change to the account-level firewall rules in 1Password. These rules restrict the networks and locations from which users can access the account. An unauthorized change may allow access from attacker-controlled or otherwise untrusted infrastructure.
Impact
Weakening or removing firewall restrictions can expose the 1Password account to login attempts from networks that were previously blocked. If an attacker also has valid credentials or a compromised session, the change can help them access vaults and the secrets stored in them.
Severity
| Severity | Condition |
|---|---|
Low | 1Password firewall rules changed |
Investigation and Remediation
Review the 1Password audit event to identify the actor, the source network, and the firewall rule changes. Verify that the change was approved and that the affected networks are expected. If it was unauthorized, restore the intended firewall policy, revoke active sessions for the acting account, and investigate other administrative actions performed by that account.