Norton LifeLock Issues a Warning for Password Manager Account Breach

 

Customers of Norton LifeLock have been the victims of a credential-stuffing attack. In accordance with the company, cyberattackers utilised a third-party list of stolen username and password combinations to attempt to hack into Norton accounts and possibly password managers. 
Gen Digital, the LifeLock brand’s owner, is mailing data-breach notifications to customers, mentioning that the activity was detected on December 12 when its IDS systems detected “an unusually high number of failed logins” on Norton accounts. According to the company, after a 10-day investigation, the activity dates back to December 1. 
While Gen Digital did not specify how many accounts were compromised, it did warn customers that the attackers had access to names, phone numbers, and mailing addresses from any Norton account. And it added, “we cannot rule out that the unauthorized third party also obtained details stored [in the Norton Password Manager], especially if your Password Manager key is identical or very similar to your Norton account password.” 
Those “details” are, of course, the strong passwords generated for any online services used by the victim, such as corporate logins, online banking, tax filing, messaging apps, e-commerce sites, and so on.
Threat actors utilize a li

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: