Report: Yahoo hack may have compromised up to 3B accounts
Yahoo Inc. may have under-reported the number of users hacked in its now infamous 2014 data breach, according to a report Monday.
Business Insider quotes “a former Yahoo executive familiar with its security practices” as saying that, given the way Yahoo’s data is organized, it’s more likely that the number of accounts stolen could be anywhere between 1 billion and 3 billion, making it the largest hack of all time.
“I believe it to be bigger than what’s being reported,” the former executive said. “How they came up with 500 [million] is a mystery.”
The executive went on to claim that all of Yahoo’s products use one main user database to authenticate users, so anyone who logs into any individual Yahoo product has their details stored in the one central place.
Yahoo first officially disclosed it had been hacked in September after it was reported earlier in August that Yahoo account details were being offered for sale on the dark web. At the time, Yahoo said the accounts of “at least” 500 million users had been compromised.
Not state sponsored
One of Yahoo’s other claims is that the hack was “state-sponsored.” That claim has been disputed by security firm Infoamor who traced the hack back to an Eastern European crime syndicate.
“Yahoo was compromised in 2014 by a group of professional blackhats who were hired to compromise customer databases from a variety of different targeted organizations,” the report notes. “The Yahoo data leak as well as the other notable exposures, opens the door to significant opportunities for cyber-espionage and targeted attacks to occur.”
Whoever did the hack or how big it may actually be besides the point given the damage it has done not only to Yahoo’s already tarnished reputation but to the potentially billions of people who have ever had a Yahoo account and password.
Image credit: Magnus Höij/Wikimedia Commons/CC by 2.0
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.