Customers are receiving data breach warnings from Gen Digital, previously Symantec Corporation and NortonLifeLock, telling them that hackers used credential-stuffing attacks to access Norton Password Manager accounts successfully.
According to a letter sample given to the Office of the Vermont Attorney General, the attacks resulted from account penetration on other platforms, not a corporation breach.
“Our own systems were not compromised. However, we strongly believe that an unauthorised third party knows and has utilised your username and password for your account,” NortonLifeLock said.
“This username and password combination may potentially also be known to others.”
The notice reveals that sometime around December 1, 2022, an attacker tried to enter Norton customer accounts using a username and password pairs they purchased from the dark web.
On December 12, 2022, the company discovered “an unusually large amount” of unsuccessful login attempts, which indicated a credential stuffing attack in which threat actors test out credentials in mass.
By the time the company had finished its internal investigation on December 22, 2022, it had been discovered that the credential stuffing attacks had successfully compromised an unspecified number of client accounts.
NortonLifeLock said: “In accessing your account with your username and password, the unauthorised third party may have viewed your first name, last name, phone number, and mailing address.”
The company claims that to prevent fraudsters from accessing affected accounts again in the future, it has reset the Norton passwords on those accounts and taken further precautions to thwart the malicious assaults.
Additionally, NortonLifeLock suggests that users set two-factor authentication to safeguard their accounts and accept the offer of a credit monitoring service.
The business has yet to reveal how many people were directly affected by this occurrence.
The recent security breach of Password Manager accounts serves as a stark reminder of the need to take online security seriously.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...