Data Breach

Yahoo Data Breach may have affected over 1 Billion users

According to a former Yahoo executive the number of affected user accounts in the Yahoo data breach may be between 1 Billion and 3 Billion.

This summer 200 million Yahoo user accounts were offered for sale in a black market on the dark web.

The company promptly started its investigation and last week confirmed the data breach, dated back at 2014 revealing that a nation-state actor has exposed at least 500 Million Yahoo user accounts.

But, now it seems that the Yahoo data breach is much extended.

The experts from the intelligence firm InfoArmor that investigated the incident claim the Yahoo data breach is the result of a cyber attack conducted by cyber criminals that later sold the Yahoo user accounts to an Eastern European nation-state actor.

yahoo-data-breachyahoo-data-breach

Such kind of data is a precious commodity for a Government that would use it to carry on cyber espionage campaigns and targeted attacks.

“Yahoo was compromised in 2014 by a group of professional blackhats who were hired to compromise customer databases from a variety of different targeted organizations. Some of their initial targets, which occurred in 2012 and 2013, are linked directly with the recent large scale data breaches of social media networks and online-services such as MySpace, Tumblr and LinkedIn. Other well-known brands have been impacted by this group but the data stolen from them is not currently available for sale or validation in the underground, as of the writing of this report.” states a blog post published by InfoArmor.

Experts from InfoArmor confirmed that the first hacker who offered for sale the huge trove of data is a threat actor nicknamed “tessa88,” he acted as a proxy between the actual bad actors.

The presence of tessa88 as a mediator allowed the hackers who breached the company to mask their identity.

“tessa88, registered on several underground communities, was the first to mention that Yahoo account credentials were available for sale. According to operative sources and long-term analysis, tessa88 acted as a proxy between the actual bad actors responsible for one of the largest hacks in history and potential buyers from various underground communities.” continues the analysis published by the company.

In May 2016 tessa88 was contacted by another hacker known as “Peace_of_Mind” (PoM), who is very active in The Real Deal Market and The Hell black markets.

Peace_of_Mind then acted as a partner with tessa88, but soon the two have had serious misunderstandings documented by InfoArmor.

A recent update on the investigation indicates that the number of affected Yahoo user accounts compromised may be between 1 Billion and 3 Billion.

According to former Yahoo executive who has spoken under a condition of anonymity, the Yahoo architecture aggregates all the user authentication data in a single database, a circumstance that suggests that the volume of compromised data is greater than revealed by the company.

“I believe it to be bigger than what’s being reported,” the executive, who no longer works for the company but claims to be in frequent contact with employees still there, including those investigating the breach, told Business Insider. “How they came up with 500 is a mystery.” reported the Business Insider.

“But the former Yahoo exec estimated the number of accounts that could have potentially been stolen could be anywhere between 1 billion and 3 billion.”

According to the source, all of Yahoo’s products share a central user database for its services, including Yahoo Mail, Finance, and Sports.

At the time of the data breach (2014), there were roughly 700 million to 1 billion active users.

The hackers compromised not only Yahoo account credentials, but also personal information included in their records such as dates of birth, phone numbers, hashed passwords, and unencrypted security answers.

Why Did Yahoo report the 500 Million number?

The sad aspect of the story is that Yahoo could have protected its users with a password reset, but according to the New York Times, the CEO Marissa Mayer gave the firm different priorities penalizing the security.

Let’s wait for a Yahoo!’s reply.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – Yahoo Data Breach, cybercrime)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Security Affairs newsletter Round 526 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…

2 hours ago

Two Linux flaws can lead to the disclosure of sensitive data

Qualys warns of two information disclosure flaws in apport and systemd-coredump, the core dump handlers in Ubuntu, Red Hat Enterprise…

20 hours ago

Meta stopped covert operations from Iran, China, and Romania spreading propaganda

Meta stopped three covert operations from Iran, China, and Romania using fake accounts to spread…

2 days ago

US Treasury sanctioned the firm Funnull Technology as major cyber scam facilitator

The U.S. sanctioned Funnull Technology and Liu Lizhi for aiding romance scams that caused major…

2 days ago

ConnectWise suffered a cyberattack carried out by a sophisticated nation state actor<gwmw style="display:none;"></gwmw><gwmw style="display:none;"></gwmw>

ConnectWise detected suspicious activity linked to a nation-state actor, impacting a small number of its…

2 days ago

Victoria’s Secret ‘s website offline following a cyberattack

Victoria’s Secret took its website offline after a cyberattack, with experts warning of rising threats…

3 days ago