1Password actor granted themselves group or vault access
Description
AlphaSOC detected a 1Password actor granting themselves group membership, a group role, or access to a vault. Self-targeted access changes can bypass the review normally applied when privileges are granted to another user and may indicate an attempt to expand access to stored secrets.
Impact
An unauthorized privilege change can allow an attacker using a compromised account to access additional vaults, passwords, API keys, and other sensitive items. The attacker may then use those secrets to access other systems or retain access after the original compromise is discovered.
Severity
| Severity | Condition |
|---|---|
Low | Actor granted themselves group membership or vault access |
Investigation and Remediation
Review the audit event to determine the acting user, the affected group or vault, and the access level granted. Confirm that the self-assignment was authorized. If not, remove the added membership, role, or vault permission; review the account's recent activity; and rotate any secrets the account could have accessed.