Yahoo Hack: Ripple Effects Could Extend Well Beyond

Advertisement
By Associated Press | Updated: 27 September 2016 18:22 IST
Highlights
  • Breach of Yahoo scale are the security equivalent of ecological disasters
  • A big worry is a cybercriminal technique known as "credential stuffing"
  • Will the big Yahoo breach mean an explosion of smaller breaches?

As investors and investigators weigh the damage of Yahoo's massive breach to the internet icon, information security experts worry that the record-breaking haul of password data could be used to open locks up and down the web.

While it's unknown to what extent the stolen data has been or will be circulating, giant breaches can send ripples of insecurity across the internet.

"Data breaches on the scale of Yahoo are the security equivalent of ecological disasters," said Matt Blaze, a security researcher who directs the Distributed Systems Lab at the University of Pennsylvania, in a message posted to Twitter.

Advertisement

(Also see: Yahoo Hack: What You Should Do if You Have an Account)

A big worry is a cybercriminal technique known as "credential stuffing," which works by throwing leaked username and password combinations at a series of websites in an effort to break in, a bit like a thief finding a ring of keys in an apartment lobby and trying them, one after the other, in every door in the building. Software makes the trial-and-error process practically instantaneous.

Advertisement

Credential stuffing typically succeeds between 0.1 percent and 2 percent of the time, according to Shuman Ghosemajumder, the chief technology officer of Mountain View, California-based Shape Security. That means cybercriminals wielding 500 million passwords could conceivably hijack tens of thousands of other accounts.

"It becomes a numbers game for them," Ghosemajumder said in a telephone interview.

Advertisement

So will the big Yahoo breach mean an explosion of smaller breaches elsewhere, like the aftershocks that follow a big quake?

Ghosemajumder doesn't think so. He said he didn't see a surge in new breaches so much as a steady increase in attempts as cybercriminals replenish their stock of freshly hacked passwords. It's conceivable as well that Yahoo passwords have already been used to hack other services; the company said the theft occurred in late 2014, meaning that the data has been compromised for as long as two years.

Advertisement

(Also see: Yahoo Hackers May Seek Intelligence, Not Riches)

"It is like an ecological disaster," Ghosemajumder said in a telephone interview. "But pick the right disaster. It's more like global warming than it is an earthquake. ... It builds up gradually."

The first hint that something was wrong at Yahoo came when Motherboard journalist Joseph Cox started receiving supposed samples of credentials hacked from the company in early July. Several weeks later, a cybercriminal using the handle "Peace" came forward with 5,000 samples - and the startling claim to be selling 200 million more.

On August 1 Cox published a story on the sale, but the journalist said he never established with any certainty where Peace's credentials came from. He noted that Yahoo said most of its passwords were secured with one encryption protocol, while Peace's sample used a second. Either Peace drew his sample from a minority of Yahoo data or he was dealing with a different set of data altogether.

"With the information available at the moment, it's more likely to be the latter," Cox said in an email Tuesday.

The Associated Press has been unable to locate Peace. The darknet market where the seller has been active in the past has been inaccessible for days, purportedly due to cyberattacks.

At the moment it's not known who holds the passwords or whether a state-sponsored actor, which Yahoo has blamed for the breach, would ever have an interest in passing its data to people like Peace .

(Also see: There's a New Way to Make Strong Passwords, and It's Way Easier)

Meanwhile, Yahoo users who recycle their passwords across different sites may be at risk. And while an internet-wide password reset is one option, Yahoo's announcement that some security questions were compromised too means that the risks associated with the breach are likely to linger.

A password can be changed, after all, but how do you reset your mother's maiden name?

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  3. Xiaomi 17 Pro Max Tipped to Come With a Secondary Display
  4. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  5. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  6. iPhone 18 Series to Feature a Smaller Dynamic Island, Tipster Claims
  7. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  8. iOS 26 Releases Today: Check Out the Notable Features
  9. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  10. Oppo Find X9 Launch Timeline Revealed: See Find X9 Pro Camera Samples
  1. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  2. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
  3. OnePlus 15 Leaked Image Hints at Redesigned Camera Module, Three Colourways
  4. Xiaomi 17 Pro Max Leaked Image Reveals Rear Display in a Nod to the 11 Ultra Ahead of September Debut
  5. Treasure Hunters Season 1 Now Streaming on JioHotstar: Everything You Need to Know
  6. London Stock Exchange Completes First Blockchain-Powered Fundraising via DMI Platform
  7. Zepto Fastest Sale Ever: Apple AirPods 4 Price Drops to Rs 9,999; Check Top Deals on Electronics, Accessories
  8. War 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  9. MeitY Proposes 20-Year Tax Holiday for Data Centres to Boost Investment: Report
  10. Resident Evil Requiem, Resident Evil 7: Biohazard and Resident Evil Village Are Coming to Switch 2 Next Year
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.