Yahoo Hackers May Seek Intelligence, Not Riches

Advertisement
By Associated Press | Updated: 26 September 2016 16:23 IST
Highlights
  • Breach could be part of a strategy that's aimed at gathering intelligence
  • Governments known to hack email accounts to keep tabs on citizens
  • No evidence yet that Yahoo attack was state-sponsored

If a foreign government is behind the massive computer attack that compromised a half billion user accounts at Yahoo, as the company says, the breach could be part of a long-term strategy that's aimed at gathering intelligence rather than getting rich.

Yahoo says the breach involved users' email addresses, passwords and other information - including birthdates - but not payment card or bank account numbers. Although the stolen data could still be used in financial crimes, such as identity theft, experts say a foreign intelligence agency might combine the Yahoo files with information from other sources to build extensive dossiers on US government or corporate officials in sensitive positions.

Advertisement

(Also see: Big Email Hack Doesn't Exactly Send the Message Yahoo Needed)

"With state-sponsored attacks, it's not just financial information that's of value," said Lance Hoffman, co-director of the Cyberspace Security and Privacy Institute at George Washington University. "In the long run, if the state accumulates a lot of information on you, and especially if it corroborates that with other sources, it can assemble a pretty good profile."

Advertisement

Governments have also been known to hack email accounts to keep tabs on their own citizens or dissidents. Experts believe that was one motive behind a 2010 hacking of Google Gmail accounts used by Chinese human rights activists.

Yahoo hasn't revealed the evidence that led it to blame a "state-sponsored actor" for the latest attack, which the Sunnyvale, California, company said occurred two years ago and was discovered only in recent weeks.

Advertisement

Some analysts warn that "state sponsored" can be a vague term. It might also be an easy excuse to deflect blame for a company's own security lapses, by suggesting it had no hope of defeating hackers who had all the resources of a government intelligence agency behind them, warned Gunter Ollmann, chief security officer at Vectra Networks, a San Jose, California, security firm.

(Also see: Yahoo Hack Raises 'Serious Questions' From EU Privacy Watchdogs)

Yahoo declined comment, but its top security official, Bob Lord, has said the company would make that claim only "when we have a high degree of confidence." In a policy statement last year, Lord also said the company wouldn't release details about why it believes attacks are state-sponsored because it doesn't want to risk disclosing its methods of investigating breaches.

Advertisement

This wouldn't be the first time that governments were implicated in high-profile hacking attacks.

US officials have hinted that China might be to blame for a 2015 breach at the US Office of Personnel Management, in which background files and even fingerprints of millions of federal employees were stolen. China denied any official involvement. More recently, news reports say US intelligence officials have blamed Russian spies for the hack of Democratic National Committee files, although Russia's government has also denied this.

Some security experts believe the OPM attack was carried out by the same hackers who also stole data files from large US insurance and health-care companies in 2014 and 2015. It may have been part of an effort to gather sensitive or compromising information to blackmail or coerce individuals working at a variety of federal agencies.

Hackers could also use such personal information to concoct bogus emails and send them to a person's Yahoo account, in what might be a sophisticated "phishing" scheme aimed at getting the target to click on a link containing "spyware" or other malicious computer code.

"They'd have the ability to conduct targeted phishing attacks against individuals with potentially valuable information, without going through their government email accounts," said Tim Erlin, senior director of security and risk strategy at Tripwire, a cyber-security firm.

Similarly, governments might want to target executives at multi-national corporations, especially if they're competing with companies based in the country that sponsored the attacks. In such cases, intelligence officials might share useful commercial secrets with their home-grown industries, said Jeremiah Grossman, an official at SentinelOne, a Silicon Valley computer security firm. He noted that the 2010 attack on Google was blamed on Chinese hackers who also targeted US companies outside the tech industry.

(Also see: Yahoo Hack: What You Should Do if You Have an Account)

In any event, security experts warn that the Yahoo breach could still put ordinary users at risk, particularly if the hacked information finds its way to online marketplaces where stolen data are bought and sold. Many people use the same email address and password for a variety of online services, where they might also have provided financial information such as credit card numbers. And hackers with access to a Yahoo email account could try to reset passwords for other services, if a user registered for those accounts with a Yahoo address.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Acer Swift Air 14 Launched With Intel Core Series 3 CPU, Lightweight Design
  2. Fable Delayed to February 2027 to Avoid Clash With GTA 6 Release
  3. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: See Price
  4. Microsoft Unveils Surface Laptop Ultra as Its Most Powerful Laptop to Date
  5. AMD Celebrates 10 Years of AM4 With Ryzen 7 5800X3D Anniversary Edition
  6. Vivo X Fold 6 Launch Timeline, Key Specifications Leaked Online
  7. HP OmniBook X 14, Ultra 16 Refreshed With Nvidia RTX Spark 'Superchip'
  8. Huawei Nova 16, Nova 16z Debut With 50-Megapixel Camera at This Price
  9. Huawei Nova 16 Pro, Nova 16 Ultra Debut With 7,000mAh Battery: See Price
  10. This Is How Samsung's Wide-Folding Handset Might Look Like in Real Life
  1. Indian Startup Pawzeeble Is Building a Pet-Focused Social Networking Space for Indian Users
  2. Asus ROG Strix Scar 18 (2026) With 240Hz 4K Mini-LED Display Showcased at Computex 2026
  3. Huawei Nova 16 Pro, Nova 16 Ultra Launched With Kirin 9010S SoC, 7,000mAh Battery: Price, Specifications
  4. Huawei Nova 16 Launched With 7,000mAh Battery, 50-Megapixel Camera, Nova 16z Tags Along: Price, Specifications
  5. Computex 2026: AMD Unveils Ryzen 7 7700X3D, Radeon RX 9070 GRE; Extends AM5 Support to 2029
  6. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: Price, Features
  7. Vivo X Fold 6 Launch Timeline Leaked; Tipped to Arrive With MediaTek Dimensity 9500 Chip
  8. HP OmniBook Ultra 16 (2026), OmniBook X 14 (2026) Unveiled With Nvidia's RTX Spark 'Superchip'
  9. Acer Swift Air 14 Launched With Intel Core Series 3 CPU, Lightweight Design at Computex 2026
  10. Microsoft Surface Laptop Ultra Announced With Blackwell RTX GPU, Nvidia RTX Spark Superchip
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.