Yahoo Says All 3 Billion Accounts Hacked in 2013 Data Theft

Advertisement
By Reuters | Updated: 4 October 2017 10:03 IST
Highlights
  • Yahoo has said that all its 3 billion accounts were hacked in 2013 theft
  • It has consequently led to exposure of new parent, Verizon
  • Verizon closed the sale of Yahoo's Internet properties earlier this year

Yahoo on Tuesday said that all 3 billion of its accounts were hacked in a 2013 data theft, tripling its earlier estimate of the size of the largest breach in history, in a disclosure that attorneys said sharply increased the legal exposure of its new owner, Verizon Communications Inc.

The news expands the likely number and claims of class action lawsuits by shareholders and Yahoo account holders, they said. Yahoo, the early face of the internet for many in the world, already faced at least 41 consumer class-action lawsuits in US federal and state courts, according to company securities filing in May.

John Yanchunis, a lawyer representing some of the affected Yahoo users, said a federal judge who allowed the case to go forward still had asked for more information to justify his clients' claims.

Advertisement

"I think we have those facts now," he said. "It's really mind-numbing when you think about it."

Advertisement

Yahoo said last December that data from more than 1 billion accounts was compromised in 2013, the largest of a series of thefts that forced Yahoo to cut the price of its assets in a sale to Verizon.

Yahoo on Tuesday said "recently obtained new intelligence" showed all user accounts had been affected. The company said the investigation indicated that the stolen information did not include passwords in clear text, payment card data, or bank account information.

Advertisement

But the information was protected with outdated, easy-to-crack encryption, according to academic experts. It also included security questions and backup email addresses, which could make it easier to break into other accounts held by the users.

Many Yahoo users have multiple accounts, so far fewer than 3 billion were affected, but the theft ranks as the largest to date, and a costly one for the internet pioneer.

Advertisement

Verizon in February lowered its original offer by $350 million for Yahoo assets in the wake of two massive cyber attacks at the internet company.

Some lawyers asked whether Verizon would look for a new opportunity to address the price.

"This is a bombshell," said Mark Molumphy, lead counsel in a shareholder derivative lawsuit against Yahoo's former leaders over disclosures about the hacks.

Verizon did not respond to a request for comment about any possible lawsuit over the deal.

Verizon, the likely main target of legal actions, also could be challenged as it launches a new brand, Oath, to link its Yahoo, AOL and Huffington Post Internet properties.

In August in the separate lawsuit brought by Yahoo's users, US Judge Lucy Koh in San Jose, California, ruled Yahoo must face nationwide litigation brought on behalf of owners accounts who said their personal information was compromised in the three breaches. Yanchunis, the lawyer for the users, said his team planned to use the new information later this month to expanding its allegations.

Also on Tuesday, Senator John Thune, chairman of the US Senate Commerce Committee, said he plans to hold a hearing later this month over massive data breaches at Equifax Inc and Yahoo. The US Securities and Exchange Commission already had been probing Yahoo over the hacks.

The closing of the Verizon deal, which was first announced in July, had been delayed as the companies assessed the fallout from two data breaches that Yahoo disclosed last year. The company paid $4.48 billion for Yahoo's core business.

A Yahoo official emphasised Tuesday that the 3 billion figure included many accounts that were opened but that were never, or only briefly, used.

The company said it was sending email notifications to additional affected user accounts.

The new revelation follows months of scrutiny by Yahoo, Verizon, cyber-security firms and law enforcement that failed to identify the full scope of the 2013 hack.

The investigation underscores how difficult it was for companies to get ahead of hackers, even when they know their networks had been compromised, said David Kennedy, chief executive of cyber-security firm TrustedSEC LLC.

Companies often do not have systems in place to gather up and store all the network activity that investigators could use to follow the hackers' tracks.

"This is a real wake up call," Kennedy said. "In most guesses, it is just guessing what they had access to."

© Thomson Reuters 2017

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  2. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  3. Bridgerton Season 4 Premieres in Two Parts on Netflix: See Details
  4. Jio Launches Happy New Year 2026 Prepaid Plans: Check Price, Benefits
  5. Samsung Galaxy A Series to Get More Expensive in India Soon, Tipster Claims
  6. Star Wars: Fate of the Old Republic Will Launch Before 2030
  7. Scientists Track Glowing Green Comet 3I/ATLAS as It Nears Earth
  8. ChatGPT's Adult Mode Might Arrive in Early 2026
  9. This Ex-OnePlus, ByteDance Director Wants to Compete With Google Lens
  1. Star Wars: Fate of the Old Republic Will Launch Before 2030, Game Director Confirms
  2. Samsung Galaxy A56 Price in India Set to Increase Soon Alongside Other A Series Models, Tipster Claims
  3. Motorola Edge 70 Launched in India With 5,000mAh Battery, 50-Megapixel Triple Rear Cameras: Price, Specifications
  4. ChatGPT Adult Mode to Reportedly Be Rolled Out in 2026, to Participate in Erotic Roleplays
  5. OnePlus 15R Price in India, Storage Configurations Leaked Days Before Launch in India
  6. Reliance Jio Launches Happy New Year 2026 Plans With Unlimited 5G Access, Google Gemini Pro
  7. Early Earth’s Deep Mantle May Have Held More Water Than Previously Believed, Study Finds
  8. Nandamuri Balakrishna's Akhanda 2 Arrives on OTT in 2026: When, Where to Watch the Film Online?
  9. Single Papa Now Streaming on OTT: All the Details About Kunal Khemu’s New Comedy Drama Series
  10. Scientists Study Ancient Interstellar Comet 3I/ATLAS, Seeking Clues to Early Star System Formation
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.