Symantec's identity theft protection service,Watch Married Woman Who Can’t Say No Online LifeLock, has reportedly exposed millions of customer email addresses due to a website bug.
LifeLock's email marketing webpage was taken down briefly after alerted by security journalist and researcher Brian Krebs, who published the flaw on his blog.
SEE ALSO: Google announces its first foray into the security key marketThe vulnerability allowed anyone with a web browser to collect customer email addresses by changing a number in the URL, which is used to unsubscribe from LifeLock's communications.
Each sequential number corresponds to a customer record, and changing that number revealed an email address on the webpage.
Krebs was alerted of the flaw by another researcher, Nathan Reese, who was able to create a script which pulled emails from the website. Reese managed to retrieve 70 emails before stopping.
This Tweet is currently unavailable. It might be loading or has been removed.
It's an attractive vulnerability to phishers wanting to target LifeLock customers, who come to the service to protect their personal data.
When Mashable attempted access of the flaw, the vulnerability was no longer working, with the webpage requiring an email to unsubscribe from LifeLock's communications.
A Symantec spokesperson explained via email that the "issue was not a vulnerability in the LifeLock member portal."
"The issue has been fixed and was limited to potential exposure of email addresses on a marketing page, managed by a third party, intended to allow recipients to unsubscribe from marketing emails," the statement added.
"Based on our investigation, aside from the 70 email address accesses reported by the researcher, we have no indication at this time of any further suspicious activity on the marketing opt-out page."
Back in 2015, LifeLock paid $100 million to settle Federal Trade Commission contempt charges after failing to secure consumers’ personal data, and allegedly engaging in deceptive advertising.
LifeLock has more than 4.5 million users, according to a 2017 press release. It was acquired by Symantec in 2016 for $2.3 billion.
UPDATE: July 26, 2018, 3:34 p.m. AEST Added a statement from Symantec.
Topics Cybersecurity
Everything coming to Netflix in April'CODA' review: A feelThe 13 best and funniest tweets of the week, including Batman and the HamburglarMost streamed TV, movies of the week: Netflix, Disney+, more.20 adoptable senior dogs in need of a new best friendApple Podcasts is finally rolling out follower analytics to podcastersTroy Kotsur wins Oscar for Best Supporting Actor, makes historyHero ruins Trump's Hollywood Walk of Fame star with a pickaxeUnprecedented picture of the sun just captured by stellar spacecraftPicsart is using artificial intelligence to create allA viral Facebook post is seeking out the owner of a lost teddy bearThe best places to find human kindness on the internetApple reportedly planning iPhone subscription offeringJane Campion becomes third woman to win Oscar for Best DirectorLego announced its new 6,020New York Times explains Trump's puzzling 'enemy of the people' tweetLet's take a moment to appreciate people with horse girl energyIPhone camera bump is reportedly getting bigger on the iPhone 14 ProRoku's best free TV channels‘Bridgerton’ Season 2 review: A satisfying, smoldering slow burn Soccer game photo is proof co 'Feel Good' brings the complex rom The Xbox Series X releases this Thanksgiving 'Birds Of Prey' joins the list of movies coming to VOD early The optimal way to remotely watch Netflix with friends Man's drunken attempt to do a backflip ends exactly as expected 'Doom Eternal' is a great way to feel less angry: Review Amazon will survive the coronavirus. But local bookstores are fighting for their lives. How to clean and disinfect your filthy keyboard or laptop Kerry Washington and Reese Witherspoon can't heat up watered How to improve your WiFi while you're stuck at home This Batman Serena Williams has a message for the creep who made 'racist' comments about her baby Netflix, YouTube to reduce streaming quality in the EU 'Promposals' get even more out of control with custom Snapchat geofilters Apple restricts iPhone sales online in wake of coronavirus supply issues Apple retail stores now closed 'until further notice' The best shows to catch up on while we're hiding from coronavirus Everything coming to (and going from) Netflix in April 2020 'The Letter for the King' falls short of the fantasy show it should be
2.7808s , 10108.921875 kb
Copyright © 2025 Powered by 【Watch Married Woman Who Can’t Say No Online】,Exquisite Information Network