Privacy Tip #149 – LifeLock Customers May be Targeted with Phishing Campaign

Robinson+Cole Data Privacy + Security Insider
Contact

We previously reported that LifeLock suffered a data breach and has been sued by the Federal Trade Commission for allegations of misleading customers [view related post], for which it settled with the FTC for $116 million [view related post] and then settled a suit alleging false statements to customers for $68 million [view related post].

If that isn’t enough, it is now being reported that LifeLock recently had a vulnerability in its website that allowed anyone with a web browser to index email addresses of millions of LifeLock’s customers. This could have allowed bad actors to have access to millions of legitimate email addresses that can be used in targeted phishing campaigns.

Apparently, LifeLock recently fixed the vulnerability, but security experts are concerned that because of the vulnerability, LifeLock customers may be targeted with phishing schemes that use LifeLock’s brand to trick them into clicking on malicious links and attachments that could introduce malware, ransomware or steal personal information of LifeLock’s customers.

LifeLock customers may wish to be extra vigilant (or as I like to say—“wicked paranoid”) about emails and phishing campaigns due to this vulnerability exposing their email addresses.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide