Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Friday September 23 2016, @01:14PM   Printer-friendly
from the ouch! dept.

Reuters via Yahoo News reports on an announcement by Yahoo! that an attacker "may have stolen names, email addresses, telephone numbers, dates of birth and encrypted passwords" for 500 million accounts in 2014. According to the announcement, the FBI is looking into the matter and that "The investigation has found no evidence that the state-sponsored actor is currently in Yahoo's network".

Yahoo Inc said on Thursday that at least 500 million of its accounts were hacked in 2014 by what it believed was a state-sponsored actor, a theft that appeared to be the world's biggest known cyber breach by far. Cyber thieves may have stolen names, email addresses, telephone numbers, dates of birth and encrypted passwords, the company said. But unprotected passwords, payment card data and bank account information did not appear to have been compromised, signalling that some of the most valuable user data was not taken. The attack on Yahoo was unprecedented in size, more than triple other large attacks on sites such as eBay Inc , and it comes to light at a difficult time for Yahoo. Chief Executive Officer Marissa Mayer is under pressure to shore up the flagging fortunes of the site founded in 1994, and the company in July agreed to a $4.83 billion cash sale of its internet business to Verizon Communications Inc . "This is the biggest data breach ever," said well-known cryptologist Bruce Schneier, adding that the impact on Yahoo and its users remained unclear because many questions remain, including the identity of the state-sponsored hackers behind it. On its website on Thursday, Yahoo encouraged users to change their passwords but did not require it.

Also covered at: Ars Technica
Computerworld
cnet
phuys.org


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by Thexalon on Friday September 23 2016, @02:35PM

    by Thexalon (636) on Friday September 23 2016, @02:35PM (#405550)

    See, your standards are looser than mine. I stop at "I never did like or trust a company".

    Or more precisely, I trust them to do whatever they think will make themselves the most money, which includes: Skimping on security unless it's likely to become a PR problem, selling off targeting based on any of my personal data they can get hold of to advertisers, and selling off any of my personal data they can get hold of if the financial conditions become desperate.

    And I don't see having any sort of emotional attachment to a for-profit corporation as a good idea. Not even the ones I work for or own.

    --
    The only thing that stops a bad guy with a compiler is a good guy with a compiler.
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2