A request that this article title be changed to Yahoo data breaches is under discussion . Please do not move this article until the discussion is closed. |
In 2013 and 2014, the American web services company Yahoo was subjected to two of the largest data breaches on record. Although Yahoo was aware, neither breach was revealed publicly until September 2016.
The 2013 data breach occurred on Yahoo servers in August 2013 and affected all three billion user accounts. The 2014 breach affected over 500 million user accounts. Both breaches are considered the largest ever discovered and included names, email addresses, phone numbers, birth dates, and security questions—both encrypted and unencrypted. When Yahoo made the breaches public in 2016, they acknowledged being aware of the second intrusion since 2014.
These incidents led to the indictment of four individuals linked to the latter breach, including the Canadian hacker Karim Baratov who received a five-year prison sentence and also prompted widespread criticism of Yahoo for their delayed response. The fallout included a U.S. $117.5 million class-action lawsuit settlement, a $35 million fine from the U.S. Securities and Exchange Commission, scrutiny by the United States Congress, and complications for Verizon Communication's 2017 acquisition of Yahoo.
The first data breach occurred on Yahoo servers in August 2013 [1] and affected all three billion user accounts. [2] [3] Yahoo announced the breach on December 14, 2016. [4] Marissa Mayer, who was CEO of Yahoo at the time of the breach, testified before Congress in 2017 that Yahoo had been unable to determine who perpetrated the 2013 breach. [5]
A year after Yahoo was identified by the American whistleblower Edward Snowden as a frequent target for state-sponsored hackers in 2013, the company hired a dedicated chief information security officer, Alex Stamos. While Stamos' hiring was praised by technology experts as showing Yahoo's commitment towards better security, Yahoo CEO Marissa Mayer had reportedly denied Stamos and his security team sufficient funds to implement the security measures they recommended, and he departed the company by 2015. [4]
During November or December 2014 a hacker, believed by the U.S. Justice Department to be the Russian national Alexey Belan, copied a November 2014 backup of Yahoo's User Account Database, containing details of over 500 million accounts to a computer under his control. [6] The User Account Database included data from over 500 million user accounts, including account names, email addresses, telephone numbers, dates of birth, hashed passwords, and in some cases, encrypted or unencrypted security questions and answers through manipulated web cookies. [7] [8] [9] The majority of Yahoo's passwords used the bcrypt hashing algorithm, which is considered difficult to crack, with the rest using the older MD5 algorithm, which can be broken rather quickly. [10]
From October 2014 to at least November 2016, Belan and at least two hackers connected to him accessed user account information and contents for various unlawful actions including searching emails for gift voucher codes, deliberately targeting the accounts of persons of interest, improving the search ranking of businesses they had an interest in, and using the Yahoo data to breach accounts on other platforms such as Gmail. [6] As part of this process, the hackers enlisted Canadian hacker Karim Baratov to break into accounts on other platforms. [11] [12]
In June 2016, it was reported that account names and passwords for about 200 million Yahoo accounts was presented for sale on the darknet market site TheRealDeal. [13] Yahoo stated it was aware of the data and was evaluating it, cautioning users about the situation but did not reset account passwords at that time. [13]
Yahoo officially reported the 2014 breach to the public on September 22, 2016. Yahoo's actions to deal with the breach included invalidating unencrypted security questions and answers and asking potentially affected users to change their passwords. [14] Yahoo also claimed that there was no evidence that the attackers were still in the system and that the attack was state-sponsored. [14] The Federal Bureau of Investigation (FBI) confirmed that it was investigating the matter. [15] The Wall Street Journal reported that a security firm, which had access to a portion of Yahoo's database, believed that the attackers were criminal in nature rather than state sponsored, and that the database had been sold repeatedly. [16]
In its November 2016 U.S. Securities and Exchange Commission (SEC) filing, Yahoo reported they had been aware of an intrusion into its network in 2014, but had not understood the extent of the breach until it began an investigation of a separate data breach incident around July 2016. [17] [18] Yahoo's previous SEC filing on September 9, prior to the breach announcement, had stated that it was not aware of any "security breaches" or "loss, theft, unauthorized access or acquisition" of user data. [19] The November filing noted that the company believed one of the data breaches had been conducted through a cookie-based attack that allowed hackers to authenticate as any other user without their password. [17] [20] [21] (In an SEC regulatory filing in 2017, Yahoo reported that 32 million accounts were accessed through this cookie-based attack through 2015 and 2016. [22] )
In December 2016, Yahoo disclosed the 2013 breach, and that one billion user accounts had been compromised. [23] Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach. [23]
Yahoo's internal review of the situation found that Mayer and other key executives knew of the intrusions but failed to inform the company or take steps to prevent further breaches. The review led to the resignation of the company's General Counsel, Ronald S. Bell by March 2017, and Mayer's $12 million equity compensation and bonus for 2016 and 2017 was pulled. [24]
On March 15, 2017, the FBI charged four men with the 2014 breach, including two that were working for Russia's Federal Security Service (FSB). In its statement, the FBI said "The criminal conduct at issue, carried out and otherwise facilitated by officers from an FSB unit that serves as the FBI's point of contact in Moscow on cybercrime matters, is beyond the pale." [25]
The four men accused include hacker Alexsey Belan who was on the FBI Ten Most Wanted Fugitives list, FSB agents Dmitry Dokuchaev and Igor Sechin who the FBI accused of paying Belan and other hackers to conduct the hack, and Canadian hacker Karim Baratov. The FBI claimed that Dokuchaev and Sushchin paid Karim Baratov to use data obtained by the Yahoo breaches to break into about 80 non-Yahoo accounts of specific targets. [26] Russian officials have denied any involvement. [27] [28]
Baratov, the only man arrested, was extradited to the United States in August 2017. [29] He pled guilty, admitting to hacking into at least 80 email accounts on behalf of Russian contacts. He was charged with nine counts of hacking, and in May 2018 sentenced to 5 years in prison and ordered to pay $2.25 million and restitution to his victims. [30] His memoir, published in 2023, describes a party lifestyle funded by hacking into email accounts of thousands of people. [31]
Yahoo's delay in discovering and reporting these breaches, as well as implementing improved security features, has been roundly criticized at all levels. [32]
Before the announcement of the breaches Verizon Communications had entered into negotiations and approval to purchase a portion of the Yahoo properties for $4.8 billion, with the deal set to close in March 2017. [33] Yahoo only disclosed the 2014 breach to Verizon two days prior to the Yahoo's September announcement. [15] Verizon CEO Lowell McAdam said he wasn't shocked by the hack, saying "we all live in an internet world, it's not a question of if you're going to get hacked but when you are going to get hacked". [34] In February 2017, Verizon and Yahoo announced that the deal will still go forward, but dropping the sale price by $350 million, down to $4.48 billion. [35] The deal officially closed at this price in June 2017, with Mayer stepping down as CEO following the closure. [36] Verizon and Yahoo agreed to jointly share ongoing costs for the government investigation of the breaches under this new term. [37] The Yahoo company, which still held those properties not purchased by Verizon, was renamed to Altaba in June 2017. [38] As Altaba was the original company, it was Altaba that was subject to a later $35 million fine from the SEC rather than Verizon. [39]
In a letter to Mayer, six U.S. Senators (Elizabeth Warren, Patrick Leahy, Al Franken, Richard Blumenthal, Ron Wyden and Ed Markey) demanded answers on when Yahoo discovered the last 2014 breach, and why it took so long to disclose it to the public, calling the time lag between the security breach and its disclosure "unacceptable". [40] [41] [42] On September 26, 2016, senator Mark Warner asked the U.S. Securities and Exchange Commission (SEC) to investigate whether Yahoo and its senior executives fulfilled their obligations under federal securities laws to properly disclose the attack. In 2017, the SEC announced a $35 million fine against Altaba for failure to disclose the 2014 breach in a timely manner. [43] [44]
In November 2016, it was reported that 23 lawsuits related to the late 2014 breach had been filed against Yahoo. [18] In one lawsuit, filed in the U.S. District Court for the Southern District of California in San Diego, the plaintiffs contended that the hack caused an "intrusion into personal financial matters." [45]
Five of these 23 cases were combined into a single suit in early December 2016. [46] [47] The case was later amended to include the updated breach information following Yahoo's announcement about the August 2013 breach. [48] Before a trial could commence, Verizon and Altaba agreed to split the cost of a $50 million settlement in October 2018 with those in the class action (an estimated 200 million total users), along with providing two years of free credit monitoring. [49] The judge rejected the settlement offer, questioning the lack of transparency of the details of the settlements, as well as high costs recouped by the lawyers through the settlement. [50] Yahoo agreed to settle for $117.5 million in April 2019, again offering affected users credit monitoring and a cash payout that depended on the number of respondents in the class. [51]
Foreign governments have also shown concerns on the several data breaches. In October 2016 the European privacy regulators Article 29 Data Protection Working Party outlined concerns about the 2014 data breach as well as allegations that the company built a system that scanned customers' incoming emails at the request of U.S. intelligence services in a letter to Yahoo. [52] [53] They asked Yahoo to communicate all aspects of the data breach to the European Union authorities, to notify the affected users of the "adverse effects" and to cooperate with all "upcoming national data protection authorities' enquiries and/or investigations". [54] Ireland's Data Protection Commissioner, (the lead European regulator on privacy issues for Yahoo because Yahoo's European headquarters are in Dublin), investigated the breach and issued a statement that "Yahoo’s oversight of the data processing operations performed by its data processor did not meet the standard required by EU data protection law" and that "Yahoo did not take sufficient reasonable steps to ensure that the data processor it engaged complied with appropriate technical security and organisational measures as required by data protection law", although no fine was issued. [55] Germany's Federal Office for Information Security criticized Yahoo following the December 2016 announcement, stating "security is not a foreign concept", and warned government and other German users to seek email and internet solutions from companies with better security approaches. [56]
Computer security is the protection of computer software, systems and networks from threats that may result in unauthorized information disclosure, theft of hardware, software, or data, as well as from the disruption or misdirection of the services they provide.
Yahoo! is an American web services provider. It is headquartered in Sunnyvale, California, and operated by the namesake company Yahoo! Inc., which is 90% owned by investment funds managed by Apollo Global Management and 10% by Verizon Communications.
The original incarnation of Yahoo! Inc. was an American multinational technology company headquartered in Sunnyvale, California. Yahoo was founded by Jerry Yang and David Filo in January 1994 and was incorporated on March 2, 1995. Yahoo was one of the pioneers of the early internet era in the 1990s. Marissa Mayer, a former Google executive, served as CEO and President of Yahoo from 2012 until June 2017.
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticated and often transparently mirror the site being targeted, allowing the attacker to observe everything while the victim navigates the site, and transverses any additional security boundaries with the victim. As of 2020, it is the most common type of cybercrime, with the FBI's Internet Crime Complaint Center reporting more incidents of phishing than any other type of computer crime.
Yahoo! Mail is an email service offered by the American company Yahoo, Inc. The service is free for personal use, with an optional monthly fee for additional features. Business email was previously available with the Yahoo! Small Business brand, before it transitioned to Verizon Small Business Essentials in early 2022. Launched on October 8, 1997, as of January 2020, Yahoo! Mail has 225 million users.
Yahoo! was founded in January 1994 by Jerry Yang and David Filo, who were electrical engineering graduates at Stanford University when they created a website named "Jerry and David's Guide to the World Wide Web". The Guide was a directory of other websites, organized in a hierarchy, as opposed to a searchable index of pages. In April 1994, Jerry and David's Guide to the World Wide Web was renamed "Yahoo!". The word "YAHOO" is a backronym for "Yet Another Hierarchically Organized Oracle" or "Yet Another Hierarchical Officious Oracle." The yahoo.com domain was created on January 18, 1995.
The Internet has a long history of turbulent relations, major maliciously designed disruptions, and other conflicts. This is a list of known and documented Internet, Usenet, virtual community and World Wide Web related conflicts, and of conflicts that touch on both offline and online worlds with possibly wider reaching implications.
The following is a timeline of events of Yahoo!, an American web services provider founded in 1994.
Verizon Communications Inc., is an American telecommunications company headquartered in New York City. It is the world's second-largest telecommunications company by revenue and its mobile network is the largest wireless carrier in the United States, with 114.8 million subscribers as of March 31, 2024.
The multinational Internet corporation Yahoo! has received criticism for a variety of issues.
The 2012 LinkedIn hack refers to the computer hacking of LinkedIn on June 5, 2012. Passwords for nearly 6.5 million user accounts were stolen. Yevgeniy Nikulin was convicted of the crime and sentenced to 88 months in prison.
In July 2015, an unknown person or group calling itself "The Impact Team" announced they had stolen the user data of Ashley Madison, a commercial website billed as enabling extramarital affairs. The hacker(s) copied personal information about the site's user base and threatened to release users' names and personal identifying information if Ashley Madison would not immediately shut down. As evidence of the seriousness of the threat, the personal information of more than 2,500 users was initially released. The company initially denied that its records were insecure, but it continued to operate.
Have I Been Pwned? is a website that allows Internet users to check whether their personal data has been compromised by data breaches. The service collects and analyzes hundreds of database dumps and pastes containing information about billions of leaked accounts, and allows users to search for their own information by entering their username or email address. Users can also sign up to be notified if their email address appears in future dumps. The site has been widely touted as a valuable resource for Internet users wishing to protect their own security and privacy. Have I Been Pwned? was created by security expert Troy Hunt on 4 December 2013.
Troy Adam Hunt is an Australian web security consultant known for public education and outreach on security topics. He created and operates Have I Been Pwned?, a data breach search website that allows users to see if their personal information has been compromised. He has also authored several popular security-related courses on Pluralsight, and regularly presents keynotes and workshops on security topics. He created ASafaWeb, a tool that formerly performed automated security analysis on ASP.NET websites.
Altaba Inc. was a non-diversified, closed-end management investment company based in New York City that was formed from the remains of the first incarnation of Yahoo! Inc. after Verizon had acquired old Yahoo's Internet business. Verizon completed its acquisition on June 13, 2017, and put the assets under a new subsidiary named Yahoo! Holdings within its newly created division, Oath. After the transaction, Yahoo! Inc. had no operating business but retained its cash holdings, partnership investments and bond portfolio, as well as certain patents that Verizon did not purchase. It reorganized as an investment fund and changed its name to Altaba Inc. on June 16. The only Yahoo! - branded interest held by Altaba was its stake in the joint venture Yahoo! Japan, which it sold to the SoftBank Group in late 2018.
Yahoo! Inc. is an American multinational technology company that focuses on media and online business. It is the second and current incarnation of the company, after Verizon Communications acquired the core assets of its predecessor and merged them with AOL in 2017. The resulting subsidiary entity was briefly called Oath Inc. In December 2018, Verizon announced it would write down the combined value of its purchases of AOL and Yahoo! by $4.6 billion, roughly half; the company would be renamed Verizon Media the following month in January 2019.
Dmitry Aleksandrovich Dokuchaev is a Russian convicted cyber criminal and a former intelligence officer of the Federal Security Service (FSB), the principal security agency of Russia. In April 2019, he was sentenced to six years in prison for treason.
ShinyHunters is a black-hat criminal hacker group that is believed to have formed in 2020 and is said to have been involved in numerous data breaches. The stolen information is often sold on the dark web.
Using a variety of techniques to bypass security measures, hackers sought access to myriad email accounts