Gen Digital said employee data was exposed in the MOVEit breach
- Organization
- Gen Digital
- Exploit
- Supply Chain Attack
- Industry
- Consumer Software
Gen Digital, the company behind the Norton, Avast, AVG, Avira and LifeLock consumer brands, confirmed in June 2023 that employee data had been exposed through the mass exploitation of Progress Software's MOVEit Transfer product.
The underlying flaw, a critical SQL injection vulnerability tracked as CVE-2023-34362, was disclosed by Progress on May 31, 2023. The Clop ransomware group had begun exploiting it days earlier and then began naming victims on its leak site, adding Norton LifeLock on June 19.
The company said the exposed information related to employees and contractors and could include names, company email addresses and employee identification numbers, with home addresses and dates of birth involved in a limited number of cases. Gen Digital said there was no impact on its core IT systems or services, and that no customer or partner data had been exposed.
Gen Digital said it investigated the scope of the issue immediately and notified the relevant data protection regulators along with the employees whose data may have been affected. It did not disclose how many people were involved. The incident was the second to affect the company in 2023, following a credential stuffing campaign earlier in the year that targeted roughly 925,000 Norton accounts.