Beyond the HubSpot Scare: How I Finally Rebuilt My Digital Security After a Near-Miss

Laptop keyboard close-up representing SaaS security and password management for marketing ops teams after a phishing prevention scare

A phishing email and a legitimate one from HubSpot look exactly the same, until you count the letters in the sender's domain. I miscounted for about half a second last fall, and that half-second is why I now have strong opinions about password management. I run marketing ops for a mid-size B2B SaaS company in Austin, which means I own more logins than anyone reasonably should, and that near miss is what turned phishing prevention from a someday task into a this-week one.

Quick housekeeping first: a few of the tools below — 1Password, RoboForm, and Incogni — are ones I pay for myself and link to as an affiliate, meaning I earn a small commission if you sign up through one of those links, at no extra cost to you. I've been running trials of most of the major password managers for a while now, and this is less a buying guide than a rundown of what actually survived contact with my actual job.

The Domain Was Off By One Letter

Back when it happened, I was mid-launch on three campaigns at once, and an email about a HubSpot billing problem landed in my inbox looking like every other notification I'd gotten for years. My cursor was already on the button before I noticed the sender's address had an extra character wedged into it, the kind of one-letter trick phishing pages have used for years and that I'd read about without ever expecting to fall for it myself. I didn't click. I also didn't feel clever about it, because I'd come within a keystroke of typing a master password into a fake login screen.

That was the part that actually rattled me: not the phishing attempt itself, those show up weekly, but how close "saving everything to Chrome" had come to costing me. I wasn't an IT person and I had zero security training, I was just someone with too many logins who finally admitted that autofill isn't a security strategy. The first real step was reducing my digital footprint after a near phishing marketing attack, and the bigger step was admitting my own team's habits were just as much the problem as any scam email.

Coffee mug beside a handwritten list of crossed-out passwords, symbolizing password management and phishing prevention cleanup

What Was Actually Wrong With Our Spreadsheet?

A few months later I finally sat down with our IT director and asked him to actually look at how our marketing team handled shared logins: a single spreadsheet on a shared drive, plain-text password columns, tabs nobody had cleaned up since two rebrands ago. I'd counted 42 duplicate passwords across our "official" login sheet before that meeting, several of which hadn't been rotated in years.

He gave me the kind of blank, over-it stare you'd expect from someone with four hundred open tickets and no bandwidth left for a marketing manager's login complaints. That stare told me nobody above me was going to fix this on a timeline I could live with, so I stopped waiting. I set up a dedicated laptop that exists for one purpose, running trial after trial of whatever vault app looked promising that month, and started treating password hygiene like an actual project instead of a someday chore, the same season I was doing laps at Barton Springs Pool instead of doomscrolling security blogs on my phone.

Watchtower, Passkeys, and Months Of Testing Vaults

Most of what I tested runs on some version of the AES encryption standard at 256 bits, a detail I stopped finding impressive once I understood the lock matters less than how the key gets handled day to day. What actually changed my habits was 1Password's Watchtower feature, which doesn't just store logins, it flags the ones that showed up in a breach you never heard about and the ones you've reused without noticing. That's a different kind of useful than a vault that just sits there being encrypted at you.

Before any of this, I'd leaned on Chrome's built-in autofill for every work account, and it never once occurred to me to question it, right up until the HubSpot email sat in a tab next to three logins Chrome had happily filled without checking whether the domain actually matched. There's a specific pause, maybe half a second, where the cursor just blinks in a login field before autofill decides whether it recognizes the site. I used to read that pause as nothing. Now I read it as the whole point: a browser filling in a password isn't the same as a vault confirming you're on the right site, and I didn't understand the difference until I'd nearly proven it the hard way.

Once I moved off Chrome's autofill and onto an actual vault, the smaller pieces started mattering: a master password that's actually long instead of clever, a secret key that lives alongside it as a second layer the master password alone can't cover, and passkeys, backed by two-factor codes for the handful of accounts that don't support passkeys yet, that replaced the "forgot password" loop I used to live in, a habit I broke after switching to 1Password passkeys earlier this year. None of that data is visible to the company running the vault, which is the whole zero-knowledge premise: they can't read your logins even if they wanted to, which is reassuring right up until it's inconvenient.

Laptop screen glowing with a vault icon, representing password management and SaaS security software testing

I Skipped The Recovery Kit And Paid For It

Zero-knowledge cuts both ways, and I found that out the annoying way. I was testing a new vault, felt confident I'd remember the setup, and skipped saving the Emergency Kit file it offered during onboarding. I didn't remember it. That cost me a few days locked out of a test vault, a small, avoidable version of a bigger lesson: the company running your vault can't reset what it never had access to in the first place, so the recovery step you skip during setup is the one that bites you later.

Sharing A Login Without Sharing A Password

The advice everyone gives is "never share passwords," which is easy to say and useless in practice when five people on a small team all need into the same LinkedIn Ads account or the same Canva subscription. Lock that down too hard and what actually happens is someone just texts the login to whoever needs it that week, which is worse than the spreadsheet ever was.

This is the one place 1Password and RoboForm both earned their subscription: their team tiers let you hand someone access to a shared vault instead of the password itself, so revoking a freelancer's access on their way out means one click instead of resetting twenty accounts on a Friday afternoon. That's a small mechanical difference that changed the actual behavior of our whole team, more than any "best practices" document ever did.

Five different colored keys on one ring, representing shared vault access for marketing ops and small team password management

The Airport Moment That Made It Stick

The switch didn't feel real in the home office, oddly enough. It felt real at the gate at Austin-Bergstrom, phone out for the boarding pass scan, when the vault unlocked itself the second I glanced at the screen, faster than I could type anything, faster than the gate agent could wave me forward. That was around six weeks into using a vault daily instead of just testing one, and after that, checking the vault before checking a link just became the default, not a decision I had to make each time. Travel Mode had already hidden the vaults I didn't need for that trip before I'd even boarded, so there wasn't anything sensitive sitting on the phone to begin with.

By then I'd also gotten better at spotting the mechanics behind that original HubSpot email: if a link doesn't autofill the way it should, I've learned to treat that as a warning sign of typosquatting rather than a glitch to click past. I've also started using Incogni to get my information pulled off the data broker sites that feed phishing lists in the first place. Proton Pass's email aliasing does something similar from the other direction, generating a throwaway address so the real one never ends up on a spam list to begin with. If you want the longer version of how I moved a few hundred logins between vaults without losing a weekend, I wrote that up separately: finding a password vault that my family and team will actually use.

A friend of mine, the kind who'd rather be at Pharr Tennis Center working on her pickleball serve than reading anything with the word "encryption" in it, texted me last month asking if a password manager was really worth paying for. I didn't try to sell her on Watchtower or zero-knowledge architecture. I told her the only thing that actually matters: autofill in a browser will fill in a password on a fake site just as happily as a real one, and a vault that checks the domain first is the only kind of convenient worth paying for. Start with something solid like 1Password, delete the spreadsheet, and stop trusting your browser to do a security tool's job.