Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Thursday December 15 2016, @10:07AM   Printer-friendly
from the who-is-next? dept.

Yahoo! has disclosed another major breach of its users' data:

Yahoo! Inc. disclosed a second major security breach that may have affected more than 1 billion users, giving an update on its probe into hacks on its system before the sale of its main web businesses to Verizon Communications Inc. The company said in a statement that it hasn't been able to identify the "intrusion" associated with this theft by a third party in August 2013.

"Yahoo believes this incident is likely distinct from the incident the company disclosed" in September, according to the statement. The shares dropped as much as 2.6 percent in extended trading after the announcement. At that time, Yahoo said the personal information of at least 500 million users was stolen in an attack on its accounts in 2014, exposing a wide swath of its users ahead of the Verizon deal. The attacker was a "state-sponsored actor," and stolen information may have included names, e-mail addresses, phone numbers, dates of birth, encrypted passwords and, in some cases, unencrypted security questions and answers, Yahoo has said.
In the 2013 hack disclosed Wednesday, Yahoo said compromised user account information may have included names, e-mail addresses, telephone numbers, dates of birth, hashed passwords and, in some cases, encrypted or unencrypted security questions and answers.

The attackers might have gotten access to less info than Uncle Sam did.

Also at TechCrunch, WSJ, and Yahoo!'s Tumblr.


Original Submission

Related Stories

Yahoo "Secretly Scanned Emails for US Authorities" 29 comments

http://www.bbc.co.uk/news/technology-37551415

Yahoo secretly scanned millions of its users' email accounts on behalf of the US government, according to a report. Reuters news agency says the firm built special software last year to comply with a classified request.

"Yahoo is a law abiding company, and complies with the laws of the United States," the tech firm said in a statement provided to the BBC.

The allegation comes less than a fortnight after Yahoo said hackers had stolen data about many of its users. Yahoo is in the process of being taken over by Verizon Communications in a $4.8bn (£3.8bn) deal. The telecoms provider declined to comment on the report.


Original Submission

Yahoo! Breach Affected 3 Billion Accounts 10 comments

Yahoo has now reported every single account was affected by a data breach in 2013:

In 2016, Yahoo disclosed that more than one billion of about three billion accounts had likely been affected by the hack. In its disclosure Tuesday, the company said all accounts were likely victimized.

Yahoo included the finding in a recent update to its Account Security Update page, saying that it found out about the wider breach through new intelligence obtained during the company's integration into Verizon Communications. Outside forensic experts assisted in the discovery, the company said.

Related: Yahoo, Inc is No More
Two Russian FSB Officers Charged Over Yahoo! Hack
Yahoo! Discloses Second Hack of More Than a Billion Accounts
Anonymous Source: Yahoo! Breach May Have Affected 1 to 3 Billion Accounts
500 Million Yahoo Accounts Hacked


Original Submission   Alternate Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Informative) by Anonymous Coward on Thursday December 15 2016, @11:39AM

    by Anonymous Coward on Thursday December 15 2016, @11:39AM (#441567)

    The attacker was a "state-sponsored actor,"

    I'd say that too. Surely a company cannot be expected to defend against state-sponsored hacking? That's the only possible answer. It couldn't be criminally negligent security practices!

  • (Score: 0) by Anonymous Coward on Thursday December 15 2016, @11:56AM

    by Anonymous Coward on Thursday December 15 2016, @11:56AM (#441570)

    "state sponsored" just means that they need to shield their computer engineers because "state actors"
    are uber hackers. be afraid of hackers. be even MOER afraid of state sponsored hackers.

    its sooo lame and implies that a regular user stands no snowball chance in hell surving on
    the internet and that only good 'ol big brother the state has the means to protect you.

    of course handing over your responsibility to secure your computer to your native state will
    accomplish only the opposite ...

    in german there is saying "he, also, only cooks with water". (as in: theres no special ingredient)

  • (Score: 2, Insightful) by Anonymous Coward on Thursday December 15 2016, @12:53PM

    by Anonymous Coward on Thursday December 15 2016, @12:53PM (#441575)

    So, there are excuses now? "State sponsored" is now an excuse to "it wasn't our fault!". But it was - your internal network is not protected. It leaked all account information and no one noticed. Stop with the excuses.

  • (Score: 3, Informative) by AthanasiusKircher on Thursday December 15 2016, @02:27PM

    by AthanasiusKircher (5291) on Thursday December 15 2016, @02:27PM (#441600) Journal

    I know this may sound a bit insulting, but should we really expect competent security practices from a company that takes its name from a fictional race of boorish idiots? (If you don't know what I'm talking about, see Jonathan Swift.)

    Oh, I know it was probably named after the yell instead, but I'm not sure that's better. It's like expecting internet security from a bunch of guys yelling "TIE-YIE-YIPPIE-YIPPIE-YAY!!"

    • (Score: 0) by Anonymous Coward on Thursday December 15 2016, @04:54PM

      by Anonymous Coward on Thursday December 15 2016, @04:54PM (#441665)

      Because "google" - an intentionally goofy mispelling of really big number - is so much better?

      Nominative determinism makes for great jokes, like Anthony Weiner and his dick pics, but assuming causality is for fools.

  • (Score: 4, Insightful) by digitalaudiorock on Thursday December 15 2016, @02:46PM

    by digitalaudiorock (688) on Thursday December 15 2016, @02:46PM (#441610) Journal

    I don't get it. Every news report I've seen on this just sort of glossed over the "2013" part, telling people to "change passwords" etc etc". WTF?...over three years ago? Call it a hunch, the damage is pretty much done at that point.

    • (Score: 1, Insightful) by Anonymous Coward on Thursday December 15 2016, @05:02PM

      by Anonymous Coward on Thursday December 15 2016, @05:02PM (#441668)

      > Call it a hunch, the damage is pretty much done at that point.

      Not if you are still using the same password on other sites. Just because your other accounts have not yet been hacked doesn't mean they still can't be hacked.

    • (Score: 5, Interesting) by takyon on Thursday December 15 2016, @05:31PM

      by takyon (881) <takyonNO@SPAMsoylentnews.org> on Thursday December 15 2016, @05:31PM (#441684) Journal

      Now that the breach has been disclosed, the attackers may accelerate their efforts to try Yahoo! passwords on other sites.

      That's if anything was taken at all. Yahoo! certainly doesn't seem to know.

      --
      [SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
  • (Score: 0) by Anonymous Coward on Thursday December 15 2016, @06:30PM

    by Anonymous Coward on Thursday December 15 2016, @06:30PM (#441714)

    And they are not allowing users to change security questions. You can't even see them.

    This might keep the same people from using your answers to get into your Yahoo account. But it seems to me that users should be able to see their own questions and answers in case they were also used on another site.

  • (Score: 2) by butthurt on Saturday December 17 2016, @04:07AM

    by butthurt (6141) on Saturday December 17 2016, @04:07AM (#442353) Journal

    The government accounts belong to current and former White House staff, U.S. congressmen and their aides, FBI agents, officials at the National Security Agency, the Central Intelligence Agency, the Office of the Director of National Intelligence, and each branch of the U.S. military. The list includes an FBI division chief and multiple special agents working around the U.S.; current and former diplomats in Pakistan, Syria and South Africa; a network administrator at NSA’s Fort Meade headquarters; the chief of an Air Force intelligence group; and a human resources manager for the CIA.

    -- https://www.bloomberg.com/news/articles/2016-12-15/stolen-yahoo-data-includes-government-employee-information [bloomberg.com]