Norton LifeLock says thousands of customer accounts breached
techcrunch.com
techcrunch.com
Accounts were breached by using credential stuffing which means using a password that was in some password breach and seeing if the users had reused their password.
LifeLock wasn't hacked at all. They're just being an overly cautious company about publishing to users whether or not those users might have been compromised.
Some users were compromised but this was due to password reuse.
The note about MFA being optional as well is concerning since that’s similarly a sign that they’re years behind even the banking industry, as an ostensible security vendor selling a password manager.
The most concerning part is that they “cannot rule out that the intruders also accessed customers’ saved passwords” — since the attacker didn’t breach their application, this suggests that they don’t have adequate logging. Every access to a saved password should be logged.