In March 2026, Aura — the identity protection service we recommend — disclosed a breach. Here's how to actually think about that, for Aura and for every other security vendor.
There's a specific kind of irony that happens in this industry: a company whose entire business is protecting people from being breached, gets breached. It's happened to Aura. It's happened to LifeLock. It will happen again, to someone. The honest question isn't whether that's alarming — it is — it's whether it should actually change how you evaluate these tools.
In March 2026, an Aura employee was phished by phone — a vishing attack — giving an attacker roughly an hour of account access. About 900,000 records were taken, but almost all of it came from a legacy marketing list Aura inherited through a 2021 acquisition, not the database behind its actual identity-monitoring product. No Social Security numbers, passwords, or financial data were involved. Aura cut off access within about an hour, brought in outside cybersecurity and legal experts, and notified law enforcement.
LifeLock (Norton) has its own history here too. In late 2022 and early 2023, a credential-stuffing attack compromised customer accounts tied to Norton's password manager specifically — a more sensitive target than a marketing list, since it threatens whatever a compromised account's password manager was protecting, not just contact information.
Contact information from a legacy marketing list — names, emails, phone numbers. The actual monitoring product and its data were never touched. Roughly 15,000–35,000 current or former customers were affected, out of the 900,000 total records, since most of the list was inactive contacts rather than active users.
Password manager accounts specifically — a direct hit on the product meant to protect users' most sensitive credentials, not a peripheral system like a marketing database.
If "has this company ever been breached" were the bar, virtually no security vendor would clear it — including ones with far better reputations than either of these. The more useful questions are what was actually exposed, and how the company responded. A breach that never touched the systems actually protecting you, disclosed quickly and handled with outside help and law enforcement involvement, is a fundamentally different event than one that hit the core product or got buried for months before anyone found out.
This is also, in a strange way, the argument for identity protection rather than against it. The entire premise of monitoring is that exposure is going to happen — to you, to the companies you use, to companies you've never heard of holding your data. The value isn't a guarantee that nothing will ever go wrong. It's shrinking the gap between when something goes wrong and when you find out, from months down to hours, so you can act before real damage is done.
Whatever monitoring service you use, it's one layer, not a guarantee. The same logic that applies to the vendor applies to your own setup: unique passwords through a password manager, multi-factor authentication on anything that matters, and a credit freeze if your Social Security number or financial data is ever actually involved in an exposure. A monitoring subscription catches things you'd otherwise miss — it was never meant to be the only thing standing between you and a bad outcome.