Yahoo Hack Was Not State-Sponsored, Claims Security Firm

Advertisement
By Reuters | Updated: 29 September 2016 10:07 IST
Highlights
  • InfoArmor challenged Yahoo's position of a nation-state actor behind hack
  • Attribution for cyber attacks is widely considered difficult
  • Yahoo said last week that it only recently discovered the intrusion

A cyber security company on Wednesday asserted that the hack of 500 million account credentials from Yahoo was the work of an Eastern European criminal gang, adding another layer of intrigue to a murky investigation into the unprecedented data heist.

Arizona-based InfoArmor issued a report whose conclusion challenged Yahoo's position that a nation-state actor orchestrated the heist, disclosed last week by the internet company. InfoArmor, which provides companies with protection against employee identify theft, said the hacked trove of user data was later sold to at least three clients, including one state-sponsored group.

Reuters was unable to verify the report's findings. Yahoo declined comment. The Federal Bureau of Investigation, which is investigating the hack, did not return a call seeking comment.

Advertisement

(Also see: Yahoo Hack: Ripple Effects Could Extend Well Beyond)

 

A US government source familiar with the Yahoo investigation said there was no hard evidence yet on whether the hack was state-sponsored. Attribution for cyber attacks is widely considered difficult in both the intelligence and research communities.

The task is made especially challenging by the fact that criminal hackers sometimes provide information to government intelligence agencies or offer their services for hire, making it hard to know who the ultimate mastermind of a hack might be.

Advertisement

Yahoo said last week that it only recently discovered the intrusion, which it blamed on a state-sponsored actor without providing technical evidence. Nation-state hackers are widely viewed as possessing more advanced capabilities than criminal groups, a perception that could benefit Yahoo as it works to minimize fallout from the breach and complete its sale to Verizon.

InfoArmor concluded the Yahoo hackers were criminal after reviewing a small sample of compromised accounts, Andrew Komarov, the firm's chief intelligence officer, said in an interview.

Advertisement

(Also see: Yahoo Hack Raises 'Serious Questions' From EU Privacy Watchdogs)

The hackers, dubbed Group E, have a track record of selling stolen personal data on the dark web, and have been previously linked to breaches at LinkedIn, Tumblr and MySpace, Komarov said.

Advertisement

"They have never been hired by anyone to hack Yahoo," Komarov, who is from Russia, said. "They were simply looking for well known sites that had many users."

In an illustration of the confusion about who carried out the hack and why, an NBC News report Wednesday interpreted Komarov's findings as pointing to the Russian government as the ultimate perpetrator.

A Wall Street Journal report, which said that InfoArmor was able to crack encrypted passwords for some Yahoo accounts provided by the newspaper, came to the opposite conclusion.

(Also see: Yahoo Hack: What You Should Do if You Have an Account)

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Z11 Turbo Design Teased; Specifications Leaked
  2. OnePlus Pad Go 2 Review
  3. Oppo Reno 15 Pro Mini Confirmed to Launch in India Alongside These Models
  4. OnePlus Reportedly Developing New Smartphone for India, Global Markets
  5. Asus VM670KA AiO All-in-One Desktop PC With 27-Inch Display Launched in India
  6. Godfather of AI Yann LeCun Reveals the Name of His New AI Startup
  7. Huawei Nova 15 Series With Kirin Chips, Up To 6,500mAh Batteries Launched
  8. Xiaomi Watch 5, Xiaomi Buds 6 to Launch Alongside Xiaomi 17 Ultra
  9. Kaya-Chan Isn't Scary Soon on OTT: Everything You Need to Know About Streaming, Plot, Cast
  10. Here's When the Redmi Pad 2 Pro 5G Will Launch in India
  1. Yann LeCun Sets Up Advanced Machine Intelligence AI Startup After Announcing Departure From Meta
  2. Nayanam Now Available For Streaming Online: What You Need to Know About This Psychological Thriller Online
  3. Kaya-Chan Isn’t Scary OTT Release Details: Know Where to Watch This Anime Horror-Comedy Series Online
  4. Samsung Galaxy S25 Series Gets One UI 8.5 Beta 2 Update in India With New Improvements, Bug Fixes
  5. Oppo Pad Air 5 Display, Battery Upgrades Confirmed Ahead of December 25 Launch in China
  6. OpenAI Upgrades ChatGPT With Adjustable Personality Traits, Response Styles
  7. Huawei Nova 15 Ultra Launched With 6,500mAh Battery, Kirin 9010S Chip, Nova 15 Pro, Nova 15 Tag Along: Price, Features
  8. Huawei Watch 10th Anniversary Edition With 1.38-inch LTPO 2.0 AMOLED Screen, HarmonyOS 6 Launched: Price, Features
  9. OnePlus Phone Codenamed ‘Volkswagen’ With Snapdragon 8s Gen 4 Chip Tipped to Launch in India, Global Markets
  10. How to Keep Your Free Perplexity Pro on Airtel: New Card Requirement Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.