01Summary
On March 8, 2012, Anonymous claimed responsibility for leaking source code belonging to Symantec's Norton AntiVirus and Norton Utilities products. The leaked data included portions of the source code for Norton 2006 and other older versions. Symantec confirmed the breach, stating that the source code was from older, discontinued product versions but acknowledging that it could potentially be used to understand Symantec's code structure and discover vulnerabilities. The leak was posted on The Pirate Bay and other file-sharing sites. Security researchers analyzed the code and identified several potential vulnerabilities that could be exploited to bypass Norton protection. The incident was a significant embarrassment for Symantec, a company whose entire business was built on providing security to others.
02Background
Symantec was one of the largest cybersecurity companies in the world, and Norton AntiVirus was installed on hundreds of millions of computers globally. The source code for security products is among the most sensitive intellectual property a security company possesses, as it reveals the exact methods used to detect and block malware.
03Key revelations
- 01Source code for a major security product was accessible to attackers.
- 02The leak demonstrated that even security companies could not protect their own intellectual property.
- 03Researchers identified potential vulnerabilities in the leaked code.
04Technical analysis
The specific method of the breach was not publicly disclosed. The leaked source code appeared to be from internal Symantec servers, suggesting either a network intrusion or insider access. The code was from older product versions (circa 2006), limiting but not eliminating the potential for finding exploitable vulnerabilities.
- Attack vector
- Unknown (likely internal network compromise or insider threat)
- Attack method
- Source Code Exfiltration and Public Release
- Exfiltration
- Public file sharing upload
- Malware type
- Data Exfiltration
MITRE ATT&CK techniques
- T1213
05Threat actor
Anonymous is a decentralized hacktivist collective. The Norton source code leak demonstrated the group's ability to penetrate even security-focused organizations and its willingness to publicly release highly sensitive intellectual property.
Aliases
- Anonymous Collective
MITRE groups
- T1190
Attribution sources
- Anonymous Statements
- Symantec Confirmation
- Security Media
06Victims and impact
Countries affected
- United States
- Global
07Data exposed
Data types
- Proprietary Source Code
- Software Architecture
- Detection Signatures
Notable documents
- Norton AntiVirus Source Code (2006 version)
- Norton Utilities Source Code
08Financial damage
Reputational damage to Symantec; security researchers identified potential vulnerabilities.
09Timeline
- 2012-03-08Anonymous leaks Norton AntiVirus and Norton Utilities source code on The Pirate Bay.
10On the record
We are Anonymous. We are Legion. We do not forgive. We do not forget.
11Reaction and fallout
Public reaction
The leak caused significant concern among Symantec customers and the broader security community. It highlighted the paradox of security companies being vulnerable to attacks themselves.
12Legal
No arrests were made. Symantec launched an internal investigation.
13Aftermath
Security improvements
- Symantec implemented enhanced source code access controls and monitoring.
14Significance and legacy
Significance
The Norton source code leak was a landmark event demonstrating that even the world's largest cybersecurity companies could be breached. It raised serious questions about the security of the products that millions relied on for protection.
Legacy
The incident became a case study in the vulnerability of security product vendors and contributed to a broader industry shift toward more robust internal security practices for protecting source code repositories.
15Disclosure and media
- Authentication
- Symantec confirmation and security researcher verification
Publishing organisations
- The Pirate Bay
16Field notes
- 01The leaked source code was for a 6-year-old version of Norton, but still provided valuable insights into Symantec's coding practices.
- 02The leak came just days after Anonymous also targeted the Vatican and other high-profile targets.
17Resolution
Symantec confirmed the breach and investigated. Older code was deemed less critical but the incident prompted security improvements.
18Sources
Official documents
- Symantec Security Advisory (2012)
References
- [1]Symantec corporate statements
- [2]ZDNet reporting
- [3]Security researcher analysis









