1Password service account created unexpectedly
Description
AlphaSOC detected creation of a 1Password service account. Service accounts provide programmatic access to selected vaults and can be used by integrations to retrieve secrets without an interactive user login. An unexpected service account may indicate an attempt to establish persistent access to the account.
Impact
An unauthorized service account can give an attacker continuing access to vault contents, including passwords, API keys, and certificates. Its access can remain available to automated tools even after a compromised user's interactive session has been revoked.
Severity
| Severity | Condition |
|---|---|
Medium | 1Password service account created unexpectedly |
Investigation and Remediation
Review the 1Password audit event to identify the creator, the new service account, its vault permissions, and any associated integration. Verify that the creation was authorized. If not, revoke the service account and its token, remove its vault access, rotate secrets it could access, and investigate the creator's account and recent administrative activity.