Identity theft protection firm 'exposes customers to phishing attacks'

LifeLock web authentication blunder leaves subscriber email addresses exposed

What happens when a company you trust to safeguard your identity actually ends up being the very organisation that leaves you vulnerable to attack?

That's what customers of identity theft protection company LifeLock appear to be discovering, after researchers learned that a flaw in the company's website could be leaving customers vulnerable to spearphishing attacks.

The flaw was first reported by security expert Brian Krebs, who was alerted to it by US researcher Nathan Reese. Reese discovered the flaw after clicking on an unsubscribe link in one of LifeLock's emails, which took him to a page where he could update his email marketing preferences.

The URL for this preference centre featured a unique subscriber key, a numerical identifier used by LifeLock to internally catalogue customers. By changing this value in the URL, Reese was able to access the preference centre for other LifeLock subscribers - which meant that he could also see their email addresses.

"It would be trivial to write a simple script that pulls down the email address of every LifeLock subscriber," Krebs said. "The design of the company's site suggests that whoever put it together lacked a basic understanding of website authentication and security."

"If I were a bad guy, I would definitely target your customers with a phishing attack because I know two things about them," said Reese. "That they're a LifeLock customer and that I have those customers' email addresses. That's a pretty sharp spear for my spearphishing right there. Plus, I definitely think the target market of LifeLock is someone who is easily spooked by the specter of cybercrime."

Readers may remember LifeLock as the company whose former CEO Todd Davis was so confident in its services that he ran numerous ads featuring his genuine social security number. He had his identity stolen at least 13 times.

LifeLock is now owned by security firm Symantec following a $2.3 billion acquisition in 2016, and as of January 2017, the company had more than 4.5 million subscribers. IT Pro has approached Symantec for comment.

Featured Resources

2021 Thales cloud security study

The challenges of cloud data protection and access management in a hybrid and multi cloud world

Free download

IDC agility assessment

The competitive advantage in adaptability

Free Download

Digital transformation insights from CIOs for CIOs

Transformation pilotes, co-pilots, and engineers

Free download

What ITDMs did next - and what they should be doing now

Enable continued collaboration and communication for hybrid workers

Recommended

Education and government most at risk from email threats
phishing

Education and government most at risk from email threats

26 Nov 2021
Attackers use CSS to fool anti-phishing systems
phishing

Attackers use CSS to fool anti-phishing systems

11 Nov 2021
X-rated phishing attacks just keep growing
phishing

X-rated phishing attacks just keep growing

4 Jun 2021
Nigerian cyber criminals target Texas unemployment system
cyber security

Nigerian cyber criminals target Texas unemployment system

27 May 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

30 Nov 2021
Microsoft seizes domains used by Chinese hacking group
cyber attacks

Microsoft seizes domains used by Chinese hacking group

7 Dec 2021
What is single sign-on (SSO)?
single sign-on (SSO)

What is single sign-on (SSO)?

2 Dec 2021