Menu
Browse

Cyber Incident Victim: Gen Digital

Date:

Dec 2022

Location:

United States of America

Summary

Gen Digital (formerly NortonLifeLock) experienced a credential-stuffing attack where threat actors used compromised credentials from external sources like the dark web to gain unauthorized access to user accounts. The attackers tested username-password combinations over a three-week period, successfully compromising some accounts and potentially accessing first names, last names, phone numbers, and email addresses. For users of Norton's password manager with reused or similar master passwords, stored credentials may have been exposed. The company confirmed its own systems weren't breached, reset affected account passwords, implemented login attempt throttling measures, and offered credit monitoring services to impacted customers.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early December 2022, Gen Digital (operating as NortonLifeLock) detected unauthorized attempts to access Norton customer accounts through credential-stuffing attacks. Between December 1 and December 22, attackers systematically tested stolen username-password combinations sourced from external platforms like darknet markets rather than Norton's own systems. The company first observed anomalous login activity on December 12 when technicians identified an unusually high volume of failed authentication attempts. Subsequent investigation confirmed that threat actors had successfully compromised some accounts during this period through brute-force methods. While Norton's infrastructure remained uncompromised, attackers obtained valid credentials for certain user accounts through these external credential verification attempts.

Cyber Incident Image

The confirmed breaches exposed affected customers' first names, last names, phone numbers, and email addresses. For users of Norton's password manager service, Gen Digital warned that attackers could potentially access stored credentials if victims reused or slightly modified their Norton account password for the password manager vault. In response, the company proactively reset Norton account passwords for impacted users to prevent further unauthorized access. Security teams implemented additional countermeasures including potential fail2ban-style IP blocking mechanisms to throttle repeated login attempts. Affected customers received notifications advising password changes across all accounts sharing credentials with their Norton login and were offered complimentary credit monitoring services. The delayed notification timeline was explicitly stated as unrelated to law enforcement investigations, though no specific rationale was provided for the communication lag between the December 22 investigation conclusion and subsequent customer alerts.

Sources
Sources available to members
1 source