Yahoo password breach extends to Gmail, Hotmail

Advertisement
By Reuters | Updated: 13 July 2012 10:08 IST
More than 400,000 Yahoo Inc user names and passwords were stolen and published on the Web, putting other websites at risk as well, after hackers exploited a vulnerability in Yahoo's computer systems.

Some logins for Google Inc, AOL Inc and Microsoft Corp services were among those compromised. The three companies said they required affected users to reset passwords for sites including Gmail, AOL, Hotmail, MSN and Live.com.

Yahoo issued a statement apologizing for the breach, the latest setback for a company that has lost two chief executives in a year and is struggling to revive stalled revenue growth.

Chairman Alfred Amoroso acknowledged that Yahoo had experienced a "tumultuous" year at its annual shareholder meeting on Thursday morning. Interim CEO Ross Levinsohn told attendees he was optimistic about the company's progress.

Advertisement

The breach prompted criticism from security experts who said that a major Internet firm like Yahoo should do a better job at protecting user data.

Advertisement

"This points to some very lax security practices," said Rob D'Ovidio, associate professor of criminal justice at Drexel University.

As an example, he noted that the hackers were able to produce more than 400,000 cleartext passwords within a day. That indicates that Yahoo either did not encrypt them at all or used an encryption method that was easy to crack, he said.

Advertisement

The professional networking service LinkedIn recently came under similar criticism. Security experts chided the company for failing to use sophisticated encryption practices to secure its passwords, millions of which were released following a breach last month.

What happened?
Yahoo spokeswoman Dana Lengkeek said "an older file" had been stolen from Yahoo Contributor Network, an Internet publishing service that Yahoo purchased about two years ago. It helps writers, photographers and videographers to sell their work over the Web.

Advertisement

"We are fixing the vulnerability that led to the disclosure of this data, changing the passwords of the affected Yahoo! users and notifying the companies whose users' accounts may have been compromised," she said.

AOL said the Yahoo data published on the Web included valid passwords for 1,699 accounts. Microsoft and Google declined to provide similar numbers.

Other firms whose customers were at risk include Comcast Corp, Verizon Communications Inc and AT&T, Rapid7 researcher Marcus Carey said. He estimated that tens of thousands of accounts of users of services other than Yahoo were affected by the breach.

AT&T and Verizon did not have any immediate comment. Officials with Comcast could not be reached.

AOL Senior Vice President David Temkin said spammers typically use credentials like the ones stolen from Yahoo to break into email accounts and use them to send out spam.

"In this case, I think we actually got ahead of it before the people who stole those accounts were able to use them," Temkin said.

The five most popular passwords in the group were "123456", "password", "welcome" and "ninja", according to an analysis by anti-virus software maker ESET.

Copyright Thomson Reuters 2012

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: AOL, Gmail, Hotmail, Yahoo, live.com, msn
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week: The Family Man Season 3, The Bengal Files, Homebound, and More
  2. Researchers Claim to Uncover Billions of WhatsApp-Registered Phone Numbers
  3. Bitcoin Drops to $86,200 as Whale Activity, Weak Macro Data Hit Market
  4. Flipkart Black Friday Sale 2025 Date Announced: Here's When It Will Begin
  5. iQOO 15 Registers Record Pre-Launch Pre-Bookings Ahead of Launch in India
  6. Poco Pad X1 Launch Date Confirmed; Will Be Equipped With This Chipset
  7. iQOO 15 Price in India, Storage Variants Reportedly Leaked
  8. You Can Now Purchase Ray-Ban Meta Glasses via Amazon, Flipkart
  9. Nothing OS 4.0 Rolls Out With Improved Animations, Extra Dark Mode
  10. Microsoft Agent 365 Will Let Enterprises Keep Track of AI Agents
  1. UC San Diego Engineers Create Wearable Patch That Controls Robots Even in Chaotic Motion
  2. Gevi Now Streaming on SunNXT: Know Everything About This Tamil Social Drama Film
  3. Harish Kalyan’s Diesel Now Streaming on Aha Tamil: What You Need to Know
  4. LG Smart TVs Gain Xbox Cloud Gaming Support in India via LG Gaming Portal
  5. iPhone 17e, Affordable MacBook Said to Launch Next Year Alongside 12th Generation iPad
  6. Lava Shark Pro 5G Reportedly Listed on IMEI Website, Hinting at Imminent Launch
  7. Microsoft Agent 365 Introduced, to Let Enterprises Keep Track of AI Agents
  8. Government Reportedly Mulling Stablecoin Adoption in Potential Policy Shift Even as RBI Flags Concerns
  9. Oppo 'PLT120' Smartphone Spotted on Chinese Certification Websites, Could Launch Soon
  10. OpenAI Is Now Rolling Out Group Chats in ChatGPT Globally to All Users
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.