EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/norton-source-code-leak-2012
336/430

File EL-0095CriticalResolvedData Breach / Source Code Leak

Norton AntiVirus Source Code Leak

Also filed as Symantec Source Code Leak · Anonymous Norton Hack 2012

Anonymous leaked the source code for older versions of Norton AntiVirus and Norton Utilities. The source code dump was posted publicly, revealing the inner workings of one of the world's most widely used security software products. The leak raised concerns about the discovery of zero-day vulnerabilities in the code.

  • #anonymous
  • #symantec
  • #norton
  • #source-code-leak
  • #antivirus
  • #cybersecurity
  • #2012
Notoriety8/10
Event
8 Mar 2012
Disclosed
8 Mar 2012
Target
Symantec (Norton)
Actor
Anonymous
Scale
Source code for Norton 2006 and Norton Utilities
Status
Resolved

01Summary

On March 8, 2012, Anonymous claimed responsibility for leaking source code belonging to Symantec's Norton AntiVirus and Norton Utilities products. The leaked data included portions of the source code for Norton 2006 and other older versions. Symantec confirmed the breach, stating that the source code was from older, discontinued product versions but acknowledging that it could potentially be used to understand Symantec's code structure and discover vulnerabilities. The leak was posted on The Pirate Bay and other file-sharing sites. Security researchers analyzed the code and identified several potential vulnerabilities that could be exploited to bypass Norton protection. The incident was a significant embarrassment for Symantec, a company whose entire business was built on providing security to others.

02Background

Symantec was one of the largest cybersecurity companies in the world, and Norton AntiVirus was installed on hundreds of millions of computers globally. The source code for security products is among the most sensitive intellectual property a security company possesses, as it reveals the exact methods used to detect and block malware.

03Key revelations

  1. 01Source code for a major security product was accessible to attackers.
  2. 02The leak demonstrated that even security companies could not protect their own intellectual property.
  3. 03Researchers identified potential vulnerabilities in the leaked code.

04Technical analysis

The specific method of the breach was not publicly disclosed. The leaked source code appeared to be from internal Symantec servers, suggesting either a network intrusion or insider access. The code was from older product versions (circa 2006), limiting but not eliminating the potential for finding exploitable vulnerabilities.

Attack vector
Unknown (likely internal network compromise or insider threat)
Attack method
Source Code Exfiltration and Public Release
Exfiltration
Public file sharing upload
Malware type
Data Exfiltration

MITRE ATT&CK techniques

  • T1213

05Threat actor

Anonymous is a decentralized hacktivist collective. The Norton source code leak demonstrated the group's ability to penetrate even security-focused organizations and its willingness to publicly release highly sensitive intellectual property.

Aliases

  • Anonymous Collective

MITRE groups

  • T1190

Attribution sources

  • Anonymous Statements
  • Symantec Confirmation
  • Security Media

06Victims and impact

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • Proprietary Source Code
  • Software Architecture
  • Detection Signatures

Notable documents

  • Norton AntiVirus Source Code (2006 version)
  • Norton Utilities Source Code

08Financial damage

Reputational damage to Symantec; security researchers identified potential vulnerabilities.

09Timeline

  1. 2012-03-08Anonymous leaks Norton AntiVirus and Norton Utilities source code on The Pirate Bay.

10On the record

We are Anonymous. We are Legion. We do not forgive. We do not forget.

Anonymous, Statement accompanying the source code release.

11Reaction and fallout

Public reaction

The leak caused significant concern among Symantec customers and the broader security community. It highlighted the paradox of security companies being vulnerable to attacks themselves.

12Legal

No arrests were made. Symantec launched an internal investigation.

13Aftermath

Security improvements

  • Symantec implemented enhanced source code access controls and monitoring.

14Significance and legacy

Significance

The Norton source code leak was a landmark event demonstrating that even the world's largest cybersecurity companies could be breached. It raised serious questions about the security of the products that millions relied on for protection.

Legacy

The incident became a case study in the vulnerability of security product vendors and contributed to a broader industry shift toward more robust internal security practices for protecting source code repositories.

15Disclosure and media

Authentication
Symantec confirmation and security researcher verification

Publishing organisations

  • The Pirate Bay

16Field notes

  1. 01The leaked source code was for a 6-year-old version of Norton, but still provided valuable insights into Symantec's coding practices.
  2. 02The leak came just days after Anonymous also targeted the Vatican and other high-profile targets.

17Resolution

Symantec confirmed the breach and investigated. Older code was deemed less critical but the incident prompted security improvements.

18Sources

Official documents

  • Symantec Security Advisory (2012)

References

  1. [1]Symantec corporate statements
  2. [2]ZDNet reporting
  3. [3]Security researcher analysis
Fact sheetEL-0095

Dates

Event
8 Mar 2012
Started
8 Mar 2012
Ended
8 Mar 2012
Duration
1 days
Discovered
8 Mar 2012
Disclosed
8 Mar 2012
Resolved
8 Mar 2012
Ongoing
No

Target

Organisation
Symantec Corporation
Type
Corporation
Sector
Cybersecurity / AntiVirus
Country
United States

Actor

Name
Anonymous
Type
Hacktivist Group
Motivation
Hacktivism and protest against perceived corporate control and surveillance, combined with anti-security establishment messaging.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Source code for Norton 2006 and Norton Utilities
Sensitivity
Top Secret
Published
Yes
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.