Hello @Billy_nich
Can you confirm the exact cookie domain shown by your browser? For example, is it:
pwnedpassword.com
pwnedpasswords.com
api.pwnedpasswords.com
haveibeenpwned.com
Norton Password Manager may perform compromised-password checks, so seeing activity related to the Pwned Passwords service can be normal. The exact domain will help determine whether the cookie is expected or something unrelated.
pwnedpasswords.com could be normal if Norton is checking passwords against breach data.
pwnedpassword.com is not the expected domain, so we should confirm it before deciding whether it is benign, unrelated, or something that deserves further scrutiny.
I suspect you may mean pwnedpasswords.com rather than pwnedpassword.com, but can you confirm the exact cookie domain? Maybe, a screenshot would be helpful. The exact spelling matters because those would be different domains.