Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / Business Continuity

Business Continuity

Credential Stuffing Attack Strikes Norton LifeLock

Credential Stuffing Attack Strikes Norton LifeLock

Randy Hall By Randy Hall Updated Jul 2024 3 min read Share

Norton LifeLock, a leading provider of identity protection and cybersecurity services, recently experienced a data breach caused by a credential stuffing attack. 

Credential stuffing is a cyberattack in which a hacker uses previously compromised information from one account to access another account, website, or service. This highlights the risks of reusing passwords across accounts, making it easier for hackers to access personal information. 

Details of the Hack

The breach occurred on December 1 and was discovered on December 12 when IT staff witnessed an unusually large amount of incorrect login attempts. As a result, the hackers may have accessed sensitive credentials such as saved passwords, usernames, phone numbers, and email addresses of approximately 6450 Norton LifeLock customers. 

Despite security experts suggesting using different passwords for each account over the years, many password manager users have admitted to reusing passwords across multiple accounts. By reusing passwords, threat actors have a greater chance of obtaining personal information from other accounts. 

Norton LifeLock Response

In response to the hack, Norton LifeLock recommends that customers change their passwords and remain vigilant for any suspicious activity. They have also emphasized the importance of multi-factor authentication, including a security key or an authentication app, which can provide your business with an extra layer of security. In addition, Norton LifeLock stated that it is cooperating with law enforcement and will investigate security measures to prevent similar attacks in the future.

Impact on Businesses

The Norton LifeLock data breach is a reminder that even well-known and reputable companies can be victims of cyber attacks. Companies should be aware of potential vulnerabilities if they use the Norton LifeLock services or a similar password manager. Threat actors could use the information accessed during the data breach to target other accounts or launch phishing attacks against employees. 

The Norton LifeLock data breach reminds us of the growing prevalence of cyber threats. Therefore, it's essential for businesses to stay informed and take proactive measures to protect their sensitive information. These measures include changing passwords regularly, monitoring accounts for suspicious activity, and implementing additional security measures like two-factor authentication. By taking these steps, organizations can help ensure that their sensitive information remains protected.

Tagged Under Business Continuity

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime