Slashdot Mirror


Yahoo Triples Estimate of Breached Accounts To 3 Billion (engadget.com)

An anonymous reader shares a report from The Wall Street Journal (Warning: source may be paywalled; alternative source): A massive data breach at Yahoo in 2013 was far more extensive than previously disclosed, affecting all of its 3 billion user accounts, new parent company Verizon Communications Inc. said on Tuesday. The figure, which Verizon said was based on new information, is three times the 1 billion accounts Yahoo said were affected when it first disclosed the breach in December 2016. The new disclosure, four months after Verizon completed its acquisition of Yahoo, shows that executives are still coming to grips with the extent of the security problem in what was already the largest hacking incident in history by number of users.

A spokesman for Oath, the new name of Verizon's Yahoo unit, said the company determined last week that the break-in was much worse than thought, after it received new information from outside the company. He declined to elaborate on the source of that information. Compromised customer information included usernames, passwords, and in some cases telephone numbers and dates of birth, the spokesman said.

14 of 41 comments (clear)

  1. 3 billion? by nospam007 · · Score: 3, Funny

    I didn't even know Yahoo still existed, so these 'accounts' must be from last millennium, no?

    1. Re:3 billion? by ark1 · · Score: 4, Insightful

      1. Allow spammers to create accounts and actively use them.
      2. Claim you have more "active" users so things must be going well.
      3. Profit?

    2. Re:3 billion? by slazzy · · Score: 2

      That could be, also personally I create a new "junk" account every few months to use before it gets overrun with junk mail, so I alone probably have 100 yahoo accounts full of junk mail...

      --
      Website Just Down For Me? Find out
    3. Re:3 billion? by lucm · · Score: 2

      I alone probably have 100 yahoo accounts full of junk mail

      Supposing that you've been doing that since the launch of Yahoo Mail, that means you created an account once every 2 or 3 months for 20 years. That's quite a commitment and a time-consuming process.

      Maybe your time is worth nothing but for $0.50 / month you can get cloud antispam from heluna, or for $5/month you can let Office365 or G Suite deal with that.

      --
      lucm, indeed.
  2. Waiting for Equifax hearing to pass this news by ark1 · · Score: 5, Insightful

    ...under radar. Well played Yahoo/Verizon.

  3. Headline next week by SuperKendall · · Score: 2

    "Yahoo announces leak of personal details for next several generations of humanity".

    Moral of story: Do not send your data back in time as a form of offsite backup, no matter how secure you think your future quantum encryption is.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
  4. There is an easier way to report this by burtosis · · Score: 2

    Simply have a story every few weeks on what data remaining hasn't been stolen. I'm guessing at this point it's the null set.

  5. AT&T? by sconeu · · Score: 2

    Just curious if this includes AT&T accounts, since AT&T had outsourced their email to Yahoo.

    --
    General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
  6. Re:What's the percentage of accounts from spambots by ShanghaiBill · · Score: 2

    I highly doubt 3B humans have ever signed up an account with Yahoo.

    They said 3B accounts, not 3B people. Nobody is claiming that these are unique individuals.

  7. Verizon paid too much by phalse+phace · · Score: 3

    Verizon should have done their due diligence on this. They probably could have gotten their $1 billion discount instead of paying $4.48 billion for Yahoo!

    Got. Ripped. Off.

  8. Story source by campuscodi · · Score: 2

    Here's the source of the WSJ's reporting: https://www.oath.com/press/yah... I have no idea why the WSJ is hiding that story behind a paywall if it's freely accessible on Oath's blog.

  9. Scope Creep by mentil · · Score: 2

    I have to hand it to the Slashdot commenters who suggested in the past that the breach would be gradually revealed to be ever bigger in scope. I imagine it'll later come out that they knew all of its accounts were breached, before the sale to Verizon, and withheld that info so they'd be bought out for a larger sum. It wouldn't surprise me if somewhere in all the Yahoo data were credentials that could've been used to hack into other, non-Yahoo computer systems, and those hacks may never be tied to this breach.

    --
    Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
  10. Wait... yahoo had 3 billion users? by gosand · · Score: 2

    I mean, gmail has just over a billion I think. Surely most of these yahoo email addresses are abandoned.

    --

    My beliefs do not require that you agree with them.

  11. Re:Look on the bright side... by msauve · · Score: 4, Funny

    "At least it can't get any worse."

    Could be raining.

    --
    "National Security is the chief cause of national insecurity." - Celine's First Law