Yahoo says one billion user accounts affected in another breach of its systems

The company say it is a different breach from the one it disclosed in September, when it said 500 million accounts were exposed

May Bulman
Wednesday 14 December 2016 18:36 EST
Comments
News of Yahoo’s latest data hack comes just months after a major breach in September in which 500 million accounts were said to be affected
News of Yahoo’s latest data hack comes just months after a major breach in September in which 500 million accounts were said to be affected

Your support helps us to tell the story

From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.

At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.

The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.

Your support makes all the difference.

American technology giant Yahoo has said it believes hackers stole data from more than one billion accounts in August 2013 – in a breach separate from the one it previously disclosed affecting 500 million accounts.

The company said the information stolen may include names, email addresses, phone numbers, birthdates and security questions and answers, but added bank account information and payment-card data were not affected.

In a statement, Yahoo said: “Yahoo believes an unauthorised third party, in August 2013, stole data associated with more than one billion user accounts. Yahoo believes this incident is likely distinct from the incident the company disclosed on September 22, 2016.

“As Yahoo previously disclosed in November, law enforcement provided the company with data files that a third party claimed was Yahoo user data. The company analysed this data with the assistance of outside forensic experts and found that it appears to be Yahoo user data.

“Based on further analysis of this data by the forensic experts, Yahoo believes an unauthorised third party, in August 2013, stole data associated with more than one billion user accounts.”

The company added that its analysis has led it to believe the same state-sponsored hackers were involved in this newly-disclosed attack.

In the statement, Yahoo advised all users to review their online accounts for suspicious activity and to change their passwords.

“Yahoo encourages users to review all of their online accounts for suspicious activity and to change their passwords and security questions and answers for any other accounts on which they use the same or similar information used for their Yahoo account,” the statement added.

The new hack revelation could be a major blow to the struggling internet giant, which is in the process of selling its core operating assets to Verizon for $4.8bn (£3.8).

The breach disclosed in September, which affected 500 million, already the biggest of its kind, had posed a threat of derailing the deal with Verizon or resulting in a reduction in the price.

In a statement, Verizon said that it would evaluate the situation as Yahoo investigates and would review the “new development before reaching any final conclusions”.

In November, Yahoo disclosed that as part of its investigation, it had received data files from law enforcement “that a third party claimed was Yahoo user data”.

Using outside forensic experts, Yahoo confirmed that this was user data but added that it had “not been able to identify the intrusion associated with this theft”.

The stolen user account information in the most recent hack may have included names, email addresses, telephone numbers, dates of birth, “hashed” passwords and, in some cases, encrypted or unencrypted security questions and answers.

The hackers did not obtain passwords in clear text, payment card data or bank account information.

Additional reporting by PA

Join our commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in