Phishing scam mimics Norton to steal email passwords under the guise of virus removal

Security researchers warn of a sophisticated phishing campaign that impersonates Norton to trick users into revealing their email passwords, using urgency and familiar security language to exploit fears of account deactivation.

Security researchers have flagged a phishing campaign that warns recipients their email account is “transmitting viruses” and will be disabled unless they run a supposed Norton cleanup tool. In reality, the message is designed to push victims to an unrelated website that imitates a mail-provider login and harvests the current password.

The lure uses urgency and fear in a familiar way. The email presents itself as an administrator notice, claims the mailbox is endangering other users and offers “Norton Web Cleaner” as the remedy. But Norton warns that scammers often impersonate trusted brands to obtain personal information, and legitimate Norton messages should come from its official domain. The Federal Trade Commission has also said scam emails frequently create pressure by threatening suspension, charges or account loss.

The technical trick is simple but effective. Clicking the cleanup link leads away from the provider and onto a lookalike page that can show a fake “Gmail Session Expired” prompt or swap in another brand’s styling. The page does not scan for malware or connect to Norton; it is built to capture the password entered by the user. Norton has separately warned against clone phishing, in which criminals copy the appearance of trusted messages to make fraudulent links seem routine.

What makes the scam persuasive is the way it borrows from real security language. A mailbox infection warning sounds plausible because email accounts are used to recover banking, cloud and shopping logins, and the prospect of deactivation can feel urgent. But a genuine provider or company administrator would normally surface security alerts through its own authenticated portal, not by asking users to enter credentials on a third-party site reached through an unsolicited message.

The safest response is to ignore the link, open the mail service directly through a trusted bookmark or app and check for real alerts there. Norton says suspicious messages should be reported through its official channels, while the FTC advises users not to trust contact details or links embedded in the email itself. If the password was entered, it should be changed immediately, sessions should be revoked and any mailbox rules or forwarding settings should be reviewed for unauthorised changes.

If anything was downloaded or installed, a full device scan is sensible, but the confirmed aim of this campaign is credential theft rather than proven malware delivery. That distinction matters: the scam is less about infecting the computer than about taking over the account and using it to access private messages, reset other logins or send further fraud to contacts.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.