New Filing Confirms Yahoo Was Aware of Large-Scale Email Hack in 2014

In September, Yahoo confirmed that at least 500 million of its users' accounts had been compromised during an attack in late 2014. Now, in a recent filing with the Securities and Exchange Commission, it was revealed that the company knew about the hack when it originally happened in 2014, but waited two years to divulge it to the public (via TechCrunch)

Describing the investigation, the new SEC filing notes a "state-sponsored actor" who gained access to the company's network in late 2014, along with Yahoo's awareness and identification of the individual in question during the same time period. Information stolen included names, email addresses, telephone numbers, dates of birth, hashed passwords, and encrypted or unencrypted security questions and answers.

yahoo
In late July 2016, a hacker claimed to have obtained certain Yahoo user data. After investigating this claim with the assistance of an outside forensic expert, the Company could not substantiate the hacker’s claim. Following this investigation, the Company intensified an ongoing broader review of the Company’s network and data security, including a review of prior access to the Company’s network by a state-sponsored actor that the Company had identified in late 2014. Based on further investigation with an outside forensic expert, the Company disclosed the Security Incident on September 22, 2016, and began notifying potentially affected users, regulators, and other stakeholders.
Now a board made up of independent counsel and a forensic expert is said to be investigating "the scope of knowledge within the company in 2014," as well as Yahoo's basic security measures and related incidents. The filing describes $1 million in losses for Yahoo relating to the security breach so far.

Additionally, Yahoo said that 23 class action lawsuits have been filed against the company by consumers targeted by the security breach in 2014, in both federal and state courts, as well as foreign courts. Plaintiffs in the cases claim to have been "harmed by the company's alleged actions and/or omissions" relating to the hack. The scope and monetary damages sought by each consumer was not divulged.

In attempts to move past the incident, Yahoo is cooperating with federal, state, and foreign governments and agencies who are investigating the hack. The biggest blowback for Yahoo might still be in its planned sale to Verizon, the latter company now asking for a $1 billion discount due to Yahoo's current turbulent drama with the news of the 2014 hack.

Tag: Yahoo


Top Rated Comments

(View all)
Avatar
15 months ago
I'd hope Yahoo gets into huge legal trouble for this, but all that does is hurt the lowly employees who lose their jobs as the company breaks apart. The executives that make these decisions never suffer any real-world consequences, and can bail out with their golden parachute as if nothing happened. We need to go after the executives and take the money out of their pockets. Once we strike fear into the heart of executives nation wide, then and only then will we have any real positive change for consumers. Executives who take clear, obviously negative actions that knowingly put their customers at risk should be held personally accountable—not the company itself. It should be a part of the assumed responsibility and risk you take in exchange for making millions of dollars per year.
Rating: 9 Votes
Avatar
15 months ago
Marissa Mayer is a joke, how on earth is she still running yahoo?
Rating: 7 Votes
Avatar
15 months ago
Screw Yahoo! Mail. I setup my own personal email server. It has classified material in it, but I don't care.
Rating: 2 Votes
Avatar
15 months ago
I thought there was a law that stated that a company must go public within 90 days if more than 500 people were affected. If that is true and Yahoo waited 2 years to go public, then I see a huge class action lawsuit coming.
Rating: 2 Votes
Avatar
15 months ago

Information stolen included names, email addresses, telephone numbers, dates of birth, hashed passwords, and encrypted or unencrypted security questions and answers.

This is why not only do I have separate, long, random, passwords for every single site (thanks 1Password), but I also never answer "security questions" with legit answers. It's like they're saying, "please set up one secure password, plus three more that someone can find out by googling you". So my "security answers" are all completely nonsensical. By the way, my parents are Atilla the Hun and Joan of Arc, and I was born in 1752 in Mare Tranquillitatis on the moon.
Rating: 2 Votes
Avatar
15 months ago

I love Keychain Access, and I keep a lot of "low value" passwords in it for easy autofill, but I use 1Password extensively for a few other reasons:

1. Apple doesn't have a Keychain Access app for iOS, so you can use it for autofill in Safari, but if I need the password that goes with a website in order to enter it into the website's corresponding iOS app, I'm out of luck - with 1Password, I can open the app to look up passwords, and copy/paste them into apps as needed.


You are not out of luck, KA works exactly as 1Password in this aspect. Settings -> Safari -> Passwords -> search for site -> long press on Password -> Copy -> Paste in app
Rating: 1 Votes
Avatar
15 months ago

As an user of yahoo email for 15 years, I'm closing the account now. Bye~


Too late, the damage has already been done, I personally dumped Yahoo years ago since it was littering my
inbox with spam and Yahoo did little to nothing to get less spam, hell, I got more and more.

I have little to no spam nowadays, I also make aliases for companies I don't fully trust.
I had no spam at all over the few years I use others including Apple but there are also others out there, big ones like Google which I don't trust either.
Rating: 1 Votes
Avatar
15 months ago

I feel like a sucker for sticking with yahoo, as it was probably my first ever experience of the internet! :eek:
Ah the joy of a 10 year old me, clicking the yes I'm 18 and over box. lol

Anyway, does anyone know better and far more secure email account?
I don't even want to entirely depend of iCloud.

Some alternatives discussed in threads like //forums.macrumors.com/threads/gmail-alternatives.2012269/
Rating: 1 Votes
Avatar
15 months ago
Mayer is a fraud.
Rating: 1 Votes
Avatar
15 months ago
1 word: ProtonMail

and thanks for this post reminding me to close my yahoo accounts
Rating: 1 Votes
[ Read All Comments ]