Issue abstract: Warning received from (I am assuming) Norton 360 concerning password compromise. Business knows NOTHING about any compromise. Also, the password involved IS NOT IN MY NORTON PASSWORD MANAGER! Also, the business IS NOT BEING MONITORED BY IDENTITY PROTECTION! So, just what in the Sam Hill is going on here???
Detailed description: I just described the issue, and I am including a screen shot of the warning I got.
Product & version number: Norton 360, v 26.3.10886 (build 26.3.10886.979)
OS details: You don’t already know my OS?? It’s MS Windows 11 Home, 25H2, installed 12/4/2024, OS build 26200.8246, Windows Feature Experience Pack 1000.26100.297.0
What is the error message you are seeing? Here is the screenshot! This is the ANOMALY! (ERROR?? Maybe!!!)
If you have any supporting screenshots, please add them:
@OmoOmo Personally, I haven’t seen this type of notification from password manager having been using it for what seems like forever. For the sake of clarity, do you indeed have an account with BOFA and its credentials are in your vault listing? Secondly, to my knowledge ( and I am NOT a Norton employee ) PWM has never asked to update a password. PWM will alert you in its web app if you have passwords that can be improved, that is the extent to which I am aware of, not this type. I have to wonder whether this is a “scare tactic” or as you stated, an anomaly.
@Selvakumar.S Could you or your team shed some light on what the OP is seeing? Thanks in advance.
SA, thank you for your reply. I do have an account, and the credentials are not in my vault listing. I do not put all my financial account info into N360, because I would rather not “hand over” my most closely-guarded financial creds (I consider that denial of info a “safeguard” against compromising my financial security). Regarding password updates, my passwords are a bit out of date. However, my BOFA password SHOULD NOT BE KNOWN to Norton AT ALL. They have my card info, yes; but not my password! So the message was baffling. I checked the BOFA website, and could find NO MENTION WHATSOEVER of any breach of passwords or other data…and that made the “red flag” fly! ALSO: Perhaps there is a very slim chance, that giving my logon creds to A DIFFERENT FINANCIAL COMPANY (so the accounts can be linked) COULD HAVE triggered some kind of security alert by Norton??? But if that is true, that would be the first time I have heard of such a thing, and for the record, the other financial company shows no news of any kind of credential breach(es). Again, thanks.
You’re welcome as always. I did tag an Admin to see if they can clarify for you. Please give them a short time to respond just to have something from Norton directly.
@OmoOmo Thank you for sharing the screenshot and details.
This is working as intended and is part of Norton Password Manager’s built‑in protection.
Even if you haven’t created or signed into a vault, Password Manager can still help keep you safe by checking passwords as they’re entered into login forms. This allows Norton to warn you early if a password you’re using has already been compromised in past data breaches.
Importantly, only a secure hash of the password is checked, not the password itself, and nothing is stored or shared in plain text.
If a match is found, the notification is simply a recommendation to change the password to help keep your account secure.
Here’s how it works:
When a password is submitted on a login form, Norton Password Manager queries Have I Been Pwned to detect the compromised password by sending the first five characters of the password hash (this is not the actual password)
The service checks whether that password hash appears in its database of known breached passwords.
If a match is found, Norton displays a notification warning the user that the password may have been compromised.
The recommendation in this case is to change the affected password to reduce the risk of account compromise.