WASHINGTON: Yahoo said Wednesday personal data from over a billion users was stolen in a hack dating back to 2013 -- twice as big as another breach disclosed just three months ago, reports AFP.
In a huge blow to the struggling internet pioneer, Yahoo said it made the discovery as it was investigating what was already the largest data breach of a single company. “Yahoo believes an unauthorized third party, in August 2013, stole data associated with more than one billion user accounts,” it said in a statement.
The news poses a fresh threat to Yahoo’s deal to sell its core operating assets to Verizon for $4.8 billion.
Yahoo said this case “is likely distinct from the incident the company disclosed on September 22, 2016” affecting 500 million users.
In November, Yahoo disclosed that as part of its investigation into the prior breach, it had received data files from law enforcement “that a third party claimed was Yahoo user data.”
Using outside forensic experts, Yahoo now confirms that this was indeed user data but added that it “has not been able to identify the intrusion associated with this theft.” The statement added that “Yahoo has taken steps to secure user accounts and is working closely with law enforcement.”
Yahoo’s chief security officer Bob Lord said in a blog post that some of the intrusions were done by hackers who accessed accounts without a password by using “forged cookies,” or data files which verify a device or user.
“We believe an unauthorized third party accessed our proprietary code to learn how to forge cookies,” he said, adding that “we have connected some of this activity to the same state-sponsored actor believed to be responsible for the data theft the company disclosed on September 22.”