Has there been any NORTON customer data breaches (not just password manager) in the last five years? Norton customer service agent told me on the phone that there was an attempt in late 2022 to access customer account data but NORTON successfully blocked it. And that’s all. Is this accurate information? Thanks in advance
bjm
July 8, 2026, 4:02pm
2
Hello @CHRISTINEM_HYDE
No, the information provided by the customer service agent is inaccurate and underplays what actually occurred. While it is true that Norton’s internal servers and core infrastructure were not directly breached or hacked, bad actors successfully compromised approximately 6,450 customer accounts in December 2022.
The agent’s claim that Norton “successfully blocked it and that’s all” is false. For thousands of users, the attack succeeded because hackers gained access to real customer accounts, forcing Norton to send out official data breach notices in January 2023.
What Actually Happened in Late 2022?
Instead of a system hack, the incident was a massive Credential Stuffing Attack .
The Method : Cybercriminals bought a list of usernames and passwords leaked from breaches of other , unrelated websites on the dark web. They used automated bots to “stuff” these combinations into the Norton login page.
The Scale : The parent company, Gen Digital (formerly NortonLifeLock), revealed that bots targeted roughly 925,000 active and inactive accounts .
The Compromise : For approximately 6,450 users , the credentials matched because those individuals reused the exact same password for their Norton account as they did on other compromised sites.
What Data Was Accessed?
For those 6,450 compromised accounts, the attackers didn’t just target password managers—they broke into the main customer account portal. According to Norton’s official disclosure to the Vermont Attorney General , the intruders viewed:
Full first and last names
Phone numbers
Mailing addresses
Potential access to the Norton Password Manager private vaults (Norton stated they could not rule out that saved vault data was exposed for these specific users).
How to Secure Your Account Now
If your account was one of the ones compromised, Norton would have forced a password reset and sent you a letter in early 2023. However, even if you weren’t affected, you should take these steps to ensure total safety:
Change Your Norton Password Immediately : Make sure it is a complex, completely unique password that you do not use on any other application or website.
Turn On Multi-Factor Authentication (MFA) : This is crucial. If MFA is enabled, an attacker cannot log into your account even if they have your correct username and password. You can set this up directly through your Norton Account Security Settings .
Audit Your Reused Passwords : Check if your email or passwords have been leaked globally using Norton’s own free Breach Detection Tool .
AI sourced content may make mistakes
2 Likes