CSIDB logo
Incident

Gen Digital

Incident posture

Attack window
Dec 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-14 00:00

Linked entities

Victim
Gen Digital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Gen Digital (formerly NortonLifeLock) experienced a credential-stuffing attack where threat actors used compromised credentials from external sources like the dark web to gain unauthorized access to user accounts. The attackers tested username-password combinations over a three-week period, successfully compromising some accounts and potentially accessing first names, last names, phone numbers, and email addresses. For users of Norton's password manager with reused or similar master passwords, stored credentials may have been exposed. The company confirmed its own systems weren't breached, reset affected account passwords, implemented login attempt throttling measures, and offered credit monitoring services to impacted customers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early December 2022, Gen Digital (operating as NortonLifeLock) detected unauthorized attempts to access Norton customer accounts through credential-stuffing attacks. Between December 1 and December 22, attackers systematically tested stolen username-password combinations sourced from external platforms like darknet markets rather than Norton's own systems. The company first observed anomalous login activity on December 12 when technicians identified an unusually high volume of failed authentication attempts. Subsequent investigation confirmed that threat actors had successfully compromised some accounts during this period through brute-force methods. While Norton's infrastructure remained uncompromised, attackers obtained valid credentials for certain user accounts through these external credential verification attempts.

The confirmed breaches exposed affected customers' first names, last names, phone numbers, and email addresses. For users of Norton's password manager service, Gen Digital warned that attackers could potentially access stored credentials if victims reused or slightly modified their Norton account password for the password manager vault. In response, the company proactively reset Norton account passwords for impacted users to prevent further unauthorized access. Security teams implemented additional countermeasures including potential fail2ban-style IP blocking mechanisms to throttle repeated login attempts. Affected customers received notifications advising password changes across all accounts sharing credentials with their Norton login and were offered complimentary credit monitoring services. The delayed notification timeline was explicitly stated as unrelated to law enforcement investigations, though no specific rationale was provided for the communication lag between the December 22 investigation conclusion and subsequent customer alerts.

Sources

Sources available to members: 1 source.

CSIDB