Identify theft protection service LifeLock reportedly exposed customer email addresses

The vulnerability allowed anyone to collect customer email addresses.
 By 
Johnny Lieu
 on 
Identify theft protection service LifeLock reportedly exposed customer email addresses
LifeLock has a reported vulnerability which exposed customer email addresses. Credit: Getty Images

Symantec's identity theft protection service, LifeLock, has reportedly exposed millions of customer email addresses due to a website bug.

LifeLock's email marketing webpage was taken down briefly after alerted by security journalist and researcher Brian Krebs, who published the flaw on his blog.

The vulnerability allowed anyone with a web browser to collect customer email addresses by changing a number in the URL, which is used to unsubscribe from LifeLock's communications.

Each sequential number corresponds to a customer record, and changing that number revealed an email address on the webpage.

Krebs was alerted of the flaw by another researcher, Nathan Reese, who was able to create a script which pulled emails from the website. Reese managed to retrieve 70 emails before stopping.

It's an attractive vulnerability to phishers wanting to target LifeLock customers, who come to the service to protect their personal data.

When Mashable attempted access of the flaw, the vulnerability was no longer working, with the webpage requiring an email to unsubscribe from LifeLock's communications.

A Symantec spokesperson explained via email that the "issue was not a vulnerability in the LifeLock member portal."

"The issue has been fixed and was limited to potential exposure of email addresses on a marketing page, managed by a third party, intended to allow recipients to unsubscribe from marketing emails," the statement added.

"Based on our investigation, aside from the 70 email address accesses reported by the researcher, we have no indication at this time of any further suspicious activity on the marketing opt-out page."

Back in 2015, LifeLock paid $100 million to settle Federal Trade Commission contempt charges after failing to secure consumers’ personal data, and allegedly engaging in deceptive advertising.

LifeLock has more than 4.5 million users, according to a 2017 press release. It was acquired by Symantec in 2016 for $2.3 billion.

UPDATE: July 26, 2018, 3:34 p.m. AEST Added a statement from Symantec.

Topics Cybersecurity

Mashable Image
Johnny Lieu

Mashable Australia's Web Culture Reporter.Reach out to me on Twitter at @Johnny_Lieu or via email at jlieu [at] mashable.com

Mashable Potato

Recommended For You
This Texas startup believes AI can identify and stop mass shooters
Members of the FBI on scene after a mass shooting in Austin, Texas in March 2026.

Sears AI chatbot chats and audio files found exposed online
A general view of newly reopened Sears department store in Downtown Burbank

How to contact Amazon customer service during your Big Spring Sale shopping spree
illustration of brown packages

Viral anti-masturbation app exposed sensitive user data
person browsing a porn site on laptop


Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!