Gen Digital, the parent company of Norton, issued a statement: it is estimated that 925000 accounts will be affected by this library collision attack.
CTOnews.com January 23 news, Norton parent company Gen Digital said in a statement shared with foreign technology media CNET, including about 8000 password manager users, it is estimated that 925000 active and inactive Norton LifeLock users will be affected.
Gen Digital, the parent company of Norton, stressed in a statement that the security incident was caused by the collision of the library, not the intrusion of the company's internal systems.
In a statement sent to CNET, Gen said:
Gen's portfolio of network security services has 500 million users, including about 8000 password manager users affected by the attack, and an estimated 925000 active and inactive users will be affected.
CTOnews.com learned that the notice indicates that on December 1, 2022, attackers attempted to log in to Norton customer accounts using the username and password pairs they purchased from the dark web. The company detected an "unusually large number" of failed login attempts on December 12, 2022, indicating that there was a library collision attack in which attackers tried a large number of passwords to log in.
As of December 22, 2022, the company had completed an internal investigation, indicating that the library collision attack had successfully hacked into an unknown number of customer accounts: "when accessing your account with your user name and password, an unauthorized third party may have checked your first name, last name, phone number, and mailing address".
Related readings:
"Norton issued a reminder: an attacker hit the library to steal user password manager credentials."