I have received a dozen phishing emails over the last 7 days, all with similat texts, spoofing the Norton360 branding, and making the false statement that "My subscription has ended", and "I am at risk". These ALL came into my Hotmail account, and ALL of them went into the SPAM folder, so no actual issues have arisen, as they were obvious fake spam emails.
What bothers me, is that firstly, there does not seem to be any easy or good way to report this to Norton, and secondly, inexperienced or non-technical "naive" users, with no "defensive tools" or knowledge of phishing scams might fall prey to these scammers, if their email client is not as good as my Outlook2019 is.
I would have thought that Norton would be a large enough company to want to actively protect their "branding" in the AV space, and have a "security and spoofing" help page to help users report these. I DID see a Norton Partners page recommending "spamcop.net" but this seems woefully inadequate for Outlook users, because the articles FAQ page stops at Outlook2007, and even then states that because Outlook re-arranges the headers, makes it impossible to see who sends them.
Here is that (very unhelpful) link mentioned above:
https://www.nortonlifelockpartner.com/security-center/report-email-spam.html and here is the Spamcop FAQ part with very outdated info: https://www.spamcop.net/fom-serve/cache/122.html
In any event, the SENDING email account or server is really only 50% of the problem, the REAL problem is the compromised servers, or sub-domains used in the URL LINKS INSIDE THE EMAIL that cause the real damage, in actually collecting the users credentials and credit card details. It is THOSE sites that need shutting down, but regular users do NOT have the knowledge or time to use "tracert", and "whois" to find who the hosting services belong to, and where the proper "abuse@" reporting emails are (if any).
This is where Norton Syamantec should be taking the lead here, to do more to protect their brand, and provide more direct help to users of their product, as most users (as a single entity) do NOT have the time, power, or resources to do that.