To protect your privacy: email us with billing or account questions instead of posting here.

If email hacked, could my 1P account be wiped?

Options
matthew2
matthew2
Community Member

Hey!

I noticed an article about if you get locked out you can automatically wipe your account if you have access to your email.

This got me thinking and concerned what if someone got into my email account, could they wipe my 1P account?

Of course I understand if someone got into my email that isn’t good because a lot of passwords could be reset to this, but not all.

Cheers

Comments

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @mdeluk: If someone has access to the email account you use for your 1Password account, they would not be able to access your data (unless you're part of a group membership and they are able to trick an admin into putting your account through recovery), but they could delete the account. You'd still be able to access your data cached locally in the 1Password app on your devices, but you're right that there's a lot of damage someone could do with access to your email.

  • matthew2
    matthew2
    Community Member
    Options

    Does the 1P at least give warning for you stop this like send another email, show a notification in app that data is being wiped in 48 hours and ability to cancel it?

  • ag_ana
    ag_ana
    1Password Alumni
    Options

    @mdeluk:

    You do get a confirmation email that you have to click on before you proceed. But in the case of someone with full access to your email account, any additional notification emails will likely be useless, as the attacker could just delete that email before you see it.

  • matthew2
    matthew2
    Community Member
    edited October 2019
    Options

    Right ok does it at least give a time period before it does it?

    Does the person only need to know my email address? Nothing else? And of course access to my email but knowledge wise?

    Matt

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    does it at least give a time period before it does it?

    @mdeluk: No. That wouldn't help anyway, since the person who's taken over your email can prevent you from ever seeing it anyway.

    Does the person only need to know my email address? Nothing else? And of course access to my email but knowledge wise?

    No. They need to have actual access to your email account. Simply knowing your email address will not allow them to delete your 1Password -- or email -- account.

This discussion has been closed.