Categories: Cyber Attack

Norton Password Manager Breached – Hackers Accessed Username and Password

Customers were notified by NortonLifeLock – Gen Digital that accounts for Norton Password Manager had been successfully breached. They made it clear that the breach was targeted at user accounts rather than the company system.

According to the letter given to the Office of the Vermont Attorney General, an unauthorized third party used credential stuffing to carry out the cyberattack. It’s possible that the hacker gained access to a customer’s account using their own username and password.

“Our own systems were not compromised. However, we strongly believe that an unauthorized third party knows and has utilized your username and password for your account,” NortonLifeLock said.

“This username and password combination may potentially also be known to others.”

Details of the Breach

As stated in the notification, an attempt was made to access Norton customer accounts sometime around December 1, 2022, by an attacker using the username and password combinations they purchased from the dark web.

As well, on December 12, 2022, the company discovered “an unusually large volume” of failed login attempts, which indicated a credential stuffing attack in which threat actors try out credentials in mass.

The company’s internal investigation was finished by December 22, 2022, and it showed that the credential-stuffing assaults had successfully compromised an unspecified number of customer accounts.

The company issued a warning that the hackers could have obtained customer names, phone numbers, and mailing addresses.

“In accessing your account with your username and password, the unauthorized third party may have viewed your first name, last name, phone number, and mailing address”, NortonLifeLock.

The company stated that as long as the user uses a similar or identical Password Manager Key, Norton cautioned that they cannot completely rule out the possibility that the hackers would be able to access the information stored in the Norton Password Manager.

The company claims it has changed the Norton passwords on affected accounts in order to stop attackers from obtaining access to accounts again in the future and has also put additional safeguards in place to thwart the fraudulent tries.

In order to secure user accounts, NortonLifeLock also suggests that customers enable two-factor authentication and accept the offer of a credit monitoring service. The exact number of people affected by this incident has not yet been disclosed by the company. 

“Systems have not been compromised, and they are safe and operational, but as is all too commonplace in today’s world for bad actors to take credentials found elsewhere, like the dark web, and create automated attacks to gain access to other unrelated accounts, as per a Gen Digital representative who communicated with BleepingComputer.

“We have been monitoring closely, flagging accounts with suspicious login attempts and proactively requiring those customers to reset their passwords upon login along with additional security measures to protect our customers”.

Network Security Checklist – Download Free E-Book

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

HCL DevOps Deploy / Launch Vulnerability Let Embed arbitrary HTML tags

Recently identified by security researchers, a new vulnerability in HCL DevOps Deploy and HCL Launch…

6 hours ago

CISA Warns of Zyxel Firewalls, CyberPanel, North Grid, & ProjectSend Flaws Exploited in Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about several vulnerabilities being actively…

8 hours ago

HackSynth : Autonomous Pentesting Framework For Simulating Cyberattacks

HackSynth is an autonomous penetration testing agent that leverages Large Language Models (LLMs) to solve…

9 hours ago

Fuji Electric Indonesia Hit by Ransomware Attack

Fuji Electric Indonesia has fallen victim to a ransomware attack, impacting its operations and raising…

10 hours ago

Thinkware Cloud APK Vulnerability Allows Code Execution With Elevated Privileges

A critical vulnerability identified as CVE-2024–53614 has been discovered in the Thinkware Cloud APK version…

11 hours ago

I-O DATA Routers Command Injection Vulnerabilities Actively Exploited in Attacks

I-O DATA DEVICE, INC. has announced that several critical vulnerabilities in their UD-LT1 and UD-LT1/EX…

12 hours ago