In a huge blow to the struggling internet pioneer, Yahoo yesterday said it made the discovery as it was investigating what was already the largest data breach of a single company.
"Yahoo believes an unauthorized third party, in August 2013, stole data associated with more than one billion user accounts," it said in a statement.
Yahoo said this case "is likely distinct from the incident the company disclosed on September 22, 2016" affecting 500 million users.
In November, Yahoo disclosed that as part of its investigation into the prior breach, it had received data files from law enforcement "that a third party claimed was Yahoo user data."
Using outside forensic experts, Yahoo now confirms that this was indeed user data but added that it "has not been able to identify the intrusion associated with this theft."
The statement added that "Yahoo has taken steps to secure user accounts and is working closely with law enforcement."
Yahoo's chief security officer Bob Lord said in a blog post that some of the intrusions were done by hackers who accessed accounts without a password by using "forged cookies," or data files which verify a device or user.
Yahoo also said it was requiring affected users to change their passwords, and had invalidated unencrypted security questions and answers.
Yahoo said in September it believed the breach of information on 500 million users was "state sponsored" but some analysts have questioned this theory.
The stolen user account information in the newly disclosed breach may have included names, email addresses, telephone numbers, dates of birth, "hashed" passwords and, in some cases, encrypted or unencrypted security questions and answers, Yahoo said.
Steve Grobman, chief technical officer at Intel Security, said the two incidents show "there were clear weaknesses in the architecture" used by Yahoo.
Large organizations holding vast amounts of user data, Grobman said, "need to rely not just on technology but use independent or internal resources to defend against attack scenarios."
Verizon said in a statement late yesterday that it would await further news of the investigation before making any decision.
"As we've said all along, we will evaluate the situation as Yahoo continues its investigation," the statement said.
Disclaimer: No Business Standard Journalist was involved in creation of this content
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
