Norton issued a reminder: an attacker hit the library to steal the user's password manager credentials
CTOnews.com Gen Digital (Symantec and Norton LifeLock) has issued a data breach notification to users, informing them that hackers have successfully hacked Norton Password Manager accounts and stolen a large amount of user data.
According to a sample letter shared by the Vermont Attorney General's Office, the attack was not caused by a vulnerability in the company, but by the disclosure of accounts on other platforms.
NortonLifeLock said: "Our own systems were not compromised. However, we strongly believe that unauthorized third parties know and use your account username and password."
CTOnews.com has learned that the notification states that on December 1, 2022, attackers attempted to log into Norton customer accounts using username and password pairs they purchased from the dark web. The company detected an "unusually large" number of failed login attempts on December 12, 2022, indicating a library collision attack in which attackers would try a large number of passwords to log in.
As of December 22, 2022, the company had completed an internal investigation indicating that the hit attack had successfully compromised an unknown number of customer accounts: "Unauthorized third parties may have viewed your name, last name, phone number and mailing address while accessing your account using your username and password."
The notice warns that for customers using Norton Password Manager, attackers may have obtained details stored in private vaults. Depending on what users store in their accounts, this could lead to the destruction of other online accounts, loss of digital assets, disclosure of secrets, etc.