Yahoo confirms massive leak of 500 million user accounts (2024)

Home>Tech

Uh oh, Yahoo.

ByNicole Gallucci on

Share on FacebookShare on TwitterShare on Flipboard

Yahoo confirms massive leak of 500 million user accounts (1)

Credit: ray wong/mashable

Yahoo officially admitted Thursday that data from at least 500 million user accounts has been stolen, confirming one of the largest security breaches ever after years of speculation via a statement on its website.

SEE ALSO:

After the sale, what happens to Yahoo's leftovers?

Yahoo confirmed that user account information was stolen from the company’s network "in late 2014 by what it believes is a state-sponsored actor." The company suggests the stolen information could include personal credentials such names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt) and even security questions and answers.

The ongoing investigation also revealed that unprotected passwords, payment card data and bank account information were not included in the stolen information, since that info isn't stored in the affected system. Yahoo stated that the company is working with law enforcement to further investigate the matter and has found no evidence that the state-sponsored actor is currently in its network.

Tweet may have been deleted

Verizon, the company that acquired Yahoo's core business for $4.83 billion in July, released a statement saying that it had only learned of the breach "within the last two days," according to USA Today.

"We understand that Yahoo is conducting an active investigation of this matter, but we otherwise have limited information and understanding of the impact," Verizon said.

On Thursday morning, Recode reported that several sources involved with Yahoo said the company — which was recently purchased by Verizon for $4.83 — finally planned to address the data breach.

Mashable Light Speed

Want more out-of-this world tech, space and science stories?

Sign up for Mashable's weekly Light Speed newsletter.

By signing up you agree to our Terms of Use and Privacy Policy.

Thanks for signing up!

According to Motherboard, the hacker, a known cybercriminal by the name of peace_of_mind, listed user credentials for 200 million Yahoo accounts on TheRealDeal, a marketplace on the dark web.

The credentials, including usernames, passwords and personal information were posted on the site for a price of $1,800.

Discussions of hacked Yahoo Mail usernames occurred back in 2014, and Motherboard reported that Yahoo acknowledged it was investigating the current data breach in the spotlight in August of this year.

In an August email, a Yahoo spokesperson told Motherboard, "We are aware of a claim ... We are committed to protecting the security of our users' information and we take any such claim very seriously.

"Our security team is working to determine the facts. Yahoo works hard to keep our users safe, and we always encourage our users to create strong passwords, or give up passwords altogether by using Yahoo Account Key, and use different passwords for different platforms."

Reports stated that in the past, the same hacker has been involved in selling illegally acquired information from Myspace,LinkedInand Tumblr.

Mashable reached out to Yahoo for comment and will update this article once we receive a response.

Additional reporting by Jason Abbruzzese.

Yahoo confirms massive leak of 500 million user accounts (2)

Nicole Gallucci

Nicole is a Senior Editor at Mashable. She primarily covers entertainment and digital culture trends, and in her free time she can be found watching TV, sending voice notes, or going viral on Twitter for admiring knitwear. You can follow her on Twitter @nicolemichele5.

Recommended For You

NYT's The Mini crossword answers for July 9

Stuck on any of the clues? We have the answers you need.

By Mashable Team

NYT's The Mini crossword answers for July 8

Stuck on any of the clues? We have the answers you need.

By Mashable Team

'Wordle' today: Here's the answer hints for July 8

Here are some tips and tricks to help you find the answer to "Wordle" #1115.

By Mashable Team

NYT Connections today: See hints and answers for July 8

Everything you need to solve 'Connections' #393.

By Mashable Team

'Wordle' today: Here's the answer hints for July 7

Here are some tips and tricks to help you find the answer to "Wordle" #1114.

By Mashable Team

Trending on Mashable

NYT Connections today: See hints and answers for July 9

Everything you need to solve 'Connections' #394.

By Mashable Team

NYT Connections today: See hints and answers for July 10

Everything you need to solve 'Connections' #395.

By Mashable Team

How streamer Pirate Software gained nearly two million subs in six months

Lightning struck twice for the game dev streamer.

By Steven Asarch

'Wordle' today: Here's the answer hints for July 10

Here are some tips and tricks to help you find the answer to "Wordle" #1117.

By Mashable Team

'Wordle' today: Here's the answer hints for July 9

Here are some tips and tricks to help you find the answer to "Wordle" #1116.

By Mashable Team

The biggest stories of the day delivered to your inbox.

This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.

Thanks for signing up. See you at your inbox!

  • TECH
  • SCIENCE
  • LIFE
  • SOCIAL GOOD
  • ENTERTAINMENT
  • BEST PRODUCTS
  • DEALS

Yahoo confirms massive leak of 500 million user accounts (23)

Mashable supports Group Black and its mission to increase greater diversity in media voices and media ownership. Group Black's collective includes Essence, TheShadeRoom and Afro-Punk.

©2005–2024 Mashable, Inc., a Ziff Davis company. All Rights Reserved.

Mashable is a registered trademark of Ziff Davis and may not be used by third parties without express written permission.

Yahoo confirms massive leak of 500 million user accounts (2024)

FAQs

Yahoo confirms massive leak of 500 million user accounts? ›

Late 2014: breach

How much are people getting from the Yahoo data breach? ›

You'll probably know by now that the impact of the breaches has led Yahoo to agree to a payout of up to $25,00 per person affected by the cyberattack, as part of a $117.5 million settlement for 194 million people. The deadline to apply for a payout—July 20—is close, so now's the time to get your claim in.

What was taken in the Yahoo data breach? ›

The data stolen was information from email accounts such as: names; phone numbers; dates-of-birth; passwords and email addresses. Encrypted and unencrypted security questions and answers were taken as well.

Is Yahoo's 2016 data breach considered the largest cyberattack in the history of the Internet? ›

Yahoo, then a publicly traded company, was acquired by Verizon in 2017 for a little over $4 billion. However, in October 2017, the company revealed that the total number of users impacted by the breach stood at 3 billion. Experts consider the hack the largest discovered in the history of the internet.

How could the Yahoo breach have been prevented? ›

The POLP could have implemented for all roles and credentials at Yahoo. Yahoo did not report the breach, which occurred in 2014, until 2016. A large proportion of the data could have been protected by communicating to their user base and asking for simple password resets.

Is the Yahoo data breach check real? ›

Yahoo is close to reaching a $117.5 million settlement in a class-action lawsuit over a series of data breaches that affected users between 2012 and 2016 — and your employees are potentially eligible for a $100 check and/or free credit monitoring if they had an account during that period.

Did Yahoo settlement payout? ›

The Settlement Administrator is working to finalize settlement payments to be sent to valid class members. An estimated mailing date will be posted as soon as possible. However, there is an expectation that payments will be made within the first half of 2023.

Was my Yahoo account breached? ›

Signs of a hacked account

You're not receiving any emails. Your Yahoo Mail is sending spam to your contacts. You see logins from unexpected locations on your recent activity page. Your account info or mail settings were changed without your knowledge.

Who owns Yahoo now? ›

Yahoo! (/ˈjɑːhuː/, styled yahoo! in its logo) is an American web services provider. It is headquartered in Sunnyvale, California, and operated by the namesake company Yahoo! Inc., which is 90% owned by investment funds managed by Apollo Global Management and 10% by Verizon Communications.

What were people with Yahoo accounts being advised to do to protect themselves? ›

People with Yahoo! accounts were advised to take several steps to protect themselves, including changing their passwords, enabling two-factor authentication, monitoring their accounts for suspicious activity, and being cautious of phishing attempts.

Which company has the largest data breach in history? ›

  1. 1. Yahoo. Year: 2013-2016. Number of records affected: Over 3 billion user accounts. ...
  2. Equifax. Year: 2017. ...
  3. 3. Facebook. Year: 2019. ...
  4. First American Financial Corporation. Year: 2019. ...
  5. Aadhaar. Year: 2018. ...
  6. MySpace. Year: 2013. ...
  7. LinkedIn. Year: 2021. ...
  8. Friend Finder Networks. Year: 2016.
Jun 28, 2024

Is Yahoo data breach among the biggest in history? ›

Look no further than the recently released 2024 Cybersecurity Almanac. In what is considered the largest data breach in history, all 3 billion Yahoo user accounts were compromised by a 2013 breach that went undetected for three years.

What is the largest data breach fine ever? ›

1. Meta (Facebook) : $1.3 Billion. In May 2023, Ireland's Data Protection Commission (DPC) concluded an enquiry into Meta Platform Ireland Limited (“Meta Ireland”) it had initiated in Aug 2020, billing the social media giant €1.2 billion ($1.3 billion) for violation of the GDPR.

What happens if personal data is leaked? ›

Data exposed during a breach creates a serious fraud risk. Sensitive information that could wind up in the hands of criminals or on the dark web after a data breach includes: Your full names. Email addresses.

What is the most famous security breach? ›

26 Biggest Data Breaches in US History
  1. 1. Yahoo! Date: 2013-2016. ...
  2. Microsoft. Date: January 2021. ...
  3. Real Estate Wealth Network. Date: December 2023. ...
  4. First American Financial Corp. Date: May 2019. ...
  5. 5. Facebook. Date: April 2021. ...
  6. LinkedIn. Date: April 2021. ...
  7. JPMorgan Chase. Date: June 2014. ...
  8. Home Depot. Date: April 2014.
Feb 20, 2024

What is the biggest password leak yet case study? ›

Dubbed RockYou2024, this colossal data dump was unveiled by a user named “ObamaCare” on a prominent hacking forum, revealing a staggering 9.9 billion unique passwords in plain text.

How much can I get for data breach? ›

There's No Set Data Breach Amount, But…

It's important to note that there's no one “set,” fixed amount for how much a person could receive from a data breach case. For example, there are so many factors that can go into it, such as the severity of the injury you suffered (typically financial damage but not always).

How much will I get from Amazon settlement fund December 23? ›

Under the settlement, each claim will be valued at $700 or the actual amount of the claim — whichever is greater — up to a maximum of $10,000. In order to receive a payment from the settlement, class members must submit a valid claim form by Dec. 23, 2022.

How many people were affected by the Yahoo data breach? ›

In December 2016, Yahoo disclosed the 2013 breach, and that one billion user accounts had been compromised. Almost a year later, in October 2017 they revised that estimate and reported that all three billion Yahoo accounts had been compromised in the breach.

How much is the payout for the OPM class action lawsuit? ›

What does the Settlement provide? Defendants will pay $63,000,000 into a Settlement Fund, which will be distributed to Class Members who submit Valid Claims. Class Members who submit Valid Claims will receive $700 or the actual amount of the claim—whichever is higher—up to a maximum of $10,000.

References

Top Articles
Metal Buildings Madera CA | Prefab Steel Building Kits for Sale Madera California
Riverwood Suburb Review & Profile | Sydney Suburb Reviews
Ogre From Halloweentown
Pulse Point Oxnard
Uta Kinesiology Advising
Review: Chained Echoes (Switch) - One Of The Very Best RPGs Of The Year
Abcm Corp Training Reliaslearning
Deep East Texas Farm And Garden - By Owner
Food And Grocery Walmart Job
Lsn Nashville Tn
Relic Gate Nms
Momokun Leaked Controversy - Champion Magazine - Online Magazine
Telegraph Ukraine podcast presenter David Knowles dies aged 32
Pokemon Infinite Fusion Good Rod
8 Restaurant-Style Dumpling Dipping Sauces You Can Recreate At Home
5Ive Brother Cause Of Death
Inside the Rise and Fall of Toys ‘R’ Us | HISTORY
Schwan's Expiration Date Decoder
Nancy Pazelt Obituary
MyChart | University Hospitals
Math Nation Algebra 2 Practice Book Answer Key
Decree Of Spite Poe
Aaa Saugus Ma Appointment
Loss Payee And Lienholder Addresses And Contact Information Updated Daily Free List Bank Of America
Closest Dollar Tree Store To My Location
Oh The Pawsibilities Salon & Stay Plano
Duen Boobs
Vidant My Chart Login
Buffalo Bills Football Reference
Jill Vasil Sell Obituary
Koinonikos Tourismos
South Park Old Fashioned Gif
Go Smiles Herndon Reviews
Papamurphys Near Me
Woude's Bay Bar Photos
Utexas Baseball Schedule 2023
Was Man über Sprints In Scrum-Projekten Wissen Sollte | Quandes
Bullmastiff vs English Mastiff: How Are They Different?
Cavender's Boot City Lafayette Photos
Dan And Riya Net Worth In 2022: How Does They Make Money?
Rush Copley Swim Lessons
Leuke tips & bezienswaardigheden voor een dagje Wijk bij Duurstede
Payback Bato
The Nun 2 Ending Explained, Summary, Cast, Plot, Review, and More
The Complete Guide to Chicago O'Hare International Airport (ORD)
Breckie Hill Shower Gif
Does Speedway Sell Elf Bars
Stuckey Furniture
Smokey's 35Th Halsted
Diora Thothub
Restaurants Near Defy Trampoline Park
Mecklenburg Warrant Search
Latest Posts
Article information

Author: Fr. Dewey Fisher

Last Updated:

Views: 5669

Rating: 4.1 / 5 (62 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Fr. Dewey Fisher

Birthday: 1993-03-26

Address: 917 Hyun Views, Rogahnmouth, KY 91013-8827

Phone: +5938540192553

Job: Administration Developer

Hobby: Embroidery, Horseback riding, Juggling, Urban exploration, Skiing, Cycling, Handball

Introduction: My name is Fr. Dewey Fisher, I am a powerful, open, faithful, combative, spotless, faithful, fair person who loves writing and wants to share my knowledge and understanding with you.