Here's the very definition of a nightmare scenario. In February 2024, Matthew Van Andel downloaded a free AI tool on the computer in his home office. Five months later, the Southern California-based engineer learned that the app included an unwelcome extra component -- an infostealing tool that gave outside attackers full access to his computer. Also: The best password managers of 2025 As Robert McMillan and Sarah Krouse reported in the Wall Street Journal, that malware was under the control of a stranger who claimed to be part of an anti-AI activist group that had targeted Van Andel's employer, the Walt Disney Company. The hacker gained access to 1Password, a password-manager that Van Andel used to store passwords and other sensitive information, as well as "session cookies," digital files stored on his computer that allowed him to access online resources including Disney's Slack channel. (If you don't have a WSJ subscription, you can read a copy of the article with no paywall at MSN.) Van Andel told the WSJ he reported the breach to Disney's cybersecurity team immediately, filed a police report, and then spent several days changing all of his passwords. To retaliate, the hackers packaged up more than a terabyte of material from Disney's internal Slack channels and published the entire cache -- 44 million messages -- online. According to Disney's cybersecurity team, the dump included "private customer information, employee passport numbers, and theme park and streaming reven...
Hackers stole this engineer's 1Password database. Could it happen to you?
ZDNet
·Ed Bott
·Published Feb 27, 2025
·Updated
Affected Software
2 affected components
1Password 1Password
Agilebits 1Password
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the theft of an engineer's 1Password database by hackers, highlighting the risks associated with downloading unknown software.
2
What security implications are discussed in the article?
The article emphasizes the dangers of using free AI tools that may compromise user credentials and sensitive data.
3
What products or software are affected by this security incident?
The affected product mentioned is 1Password, developed by AgileBits.
4
How did the engineer's data get compromised?
The engineer unknowingly downloaded a free AI tool that facilitated the hacking incident.
5
What precautions can users take to protect their password databases?
Users should avoid downloading untrusted software and consider using multi-factor authentication for added security.