Yahoo: 3 billion accounts breached in 2013 attack

  • Comments
  • Print
Listen to this story

Subscriber Benefit

As a subscriber you can listen to articles at work, in the car, or while you work out. Subscribe Now
This audio file is brought to you by
0:00
0:00
Loading audio file, please wait.
  • 0.25
  • 0.50
  • 0.75
  • 1.00
  • 1.25
  • 1.50
  • 1.75
  • 2.00

Yahoo has tripled down on what was already the largest data breach in history, saying it affected all 3 billion accounts on its service, not the 1 billion it revealed late last year.

The company announced Tuesday that it has sent emails providing notice to additional user accounts affected by the August 2013 data theft.

The breach now affects a number that represents nearly "half the world," said Sam Curry, chief security officer for Boston-based firm Cybereason, though there's likely to be more accounts than actual users.

"Whether it's 1 billion or 3 billion is largely immaterial. Assume it affects you," Curry said. "Privacy is really the victim here."

Yahoo first disclosed the breach in December . The stolen information included names, email addresses, phone numbers, birthdates and security questions and answers.

Following its acquisition by Verizon in June, Yahoo says, it obtained new intelligence while investigating the breach with help from outside forensic experts. It says the stolen customer information did not include passwords in clear text, payment card data or bank account information.

Yahoo had already required users to change their passwords and invalidate security questions so they couldn't be used to hack into accounts.

The disclosure is also a huge embarrassment for Verizon, which has just started running TV ads for its new subsidiary Oath, which will consist of Yahoo and AOL services.

Verizon spokesman David Samberg said the company has no regrets about buying Yahoo, despite the latest revelation.

Companies often don't know the full extent of a breach and have to revise statements about how it affects customers years later, said Ben Johnson, co-founder and chief technology officer for Obsidian Security, based in Newport Beach, California. Johnson said Yahoo might never know exactly what was accessed.

"The fact is attackers are having field days and the problem is only going to get worse," he said.

Please enable JavaScript to view this content.

Story Continues Below

Editor's note: You can comment on IBJ stories by signing in to your IBJ account. If you have not registered, please sign up for a free account now. Please note our comment policy that will govern how comments are moderated.

Get the best of Indiana business news. ONLY $1/week Subscribe Now

Get the best of Indiana business news. ONLY $1/week Subscribe Now

Get the best of Indiana business news. ONLY $1/week Subscribe Now

Get the best of Indiana business news. ONLY $1/week Subscribe Now

Get the best of Indiana business news.

Limited-time introductory offer for new subscribers

ONLY $1/week

Cancel anytime

Subscribe Now

Already a paid subscriber? Log In

Get the best of Indiana business news.

Limited-time introductory offer for new subscribers

ONLY $1/week

Cancel anytime

Subscribe Now

Already a paid subscriber? Log In

Get the best of Indiana business news.

Limited-time introductory offer for new subscribers

ONLY $1/week

Cancel anytime

Subscribe Now

Already a paid subscriber? Log In

Get the best of Indiana business news.

Limited-time introductory offer for new subscribers

ONLY $1/week

Cancel anytime

Subscribe Now

Already a paid subscriber? Log In