Data breach affected more than 1 bn accounts: Yahoo

Image
IANS New York
Last Updated : Dec 15 2016 | 2:42 PM IST

Yahoo has disclosed a new security breach that may have affected more than one billion user accounts.

The breach dates back to 2013 and is thought to be separate from a massive cyber security incident announced in September, the company revealed on Wednesday.

"For potentially affected accounts, the stolen user account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (using MD5) and, in some cases, encrypted or unencrypted security questions and answers," said Bob Lord, Chief Information Security Officer, Yahoo, in a blog post.

The company previously disclosed that outside forensic experts were investigating the creation of forged cookies that could allow an intruder to access users' accounts without a password.

"Based on the ongoing investigation, we believe an unauthorised third party accessed our proprietary code to learn how to forge cookies. The outside forensic experts have identified user accounts for which they believe forged cookies were taken or used," Lord said.

Yahoo says it was notifying the account holders affected. They will be required to change their passwords.

"We have also invalidated unencrypted security questions and answers so that they cannot be used to access an account," added Lord.

Yahoo said it had connected some of this activity to the same state-sponsored actor believed to be responsible for the data theft disclosed on September 22.

--IANS

anuj/na/mr

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Dec 15 2016 | 2:34 PM IST

Next Story