Yahoo disclosed two massive intrusions that together affected more than 1.5 billion user accounts, including a 2014 breach impacting at least 500 million accounts and a separate 2013 breach affecting more than 1 billion accounts. Reporting said the company detected signs of the 2014 intrusion well before its public disclosure but did not fully understand the scope until a later review in 2016, while investigators also examined evidence that attackers may have accessed some accounts without passwords by using forged cookies and stolen proprietary code. Yahoo attributed the 2014 attack to a state-backed actor, and later U.S. authorities described a Russian-linked operation that stole account data and internal secrets tied to the campaign.

See attribution, scope, and your downstream exposure.
12 events from the most recent confirmed update back to the earliest known activity.
On 2018-04-24, the SEC announced a $35 million penalty against Altaba, Yahoo's successor entity, for failing to timely disclose the 2014 data breach to investors. The enforcement action focused on Yahoo's delay in informing the market after learning of the incident.
On 2017-03-15, U.S. authorities announced charges against two Russian FSB officers and two criminal hackers for the Yahoo intrusions. Investigators said the operation enabled the theft of account data and account secrets used to target specific users.
On 2017-03-01, Yahoo disclosed that attackers used forged cookies to access about 32 million user accounts between 2015 and 2016. The company said the activity was linked to the same state-sponsored actor associated with the 2014 breach, adding new detail on the scope of account compromise.
By December 2016, Yahoo disclosed that attackers had accessed proprietary code used to forge cookies and linked some of that activity to the same state-sponsored actor believed responsible for the 2014 breach. This indicated attackers may have accessed some accounts without needing passwords.
On 2016-12-14, Yahoo announced that a separate August 2013 breach had compromised data from more than 1 billion user accounts. The disclosure intensified scrutiny of Yahoo's security practices and further complicated Verizon's acquisition negotiations.
By November 2016, Yahoo said it had formed an independent committee with outside counsel and a forensic expert to examine what the company knew internally about the 2014 breach. The company also disclosed ongoing investigation into possible cookie-based account access without passwords.
On 2016-09-22, Yahoo publicly disclosed that a 2014 breach had exposed data from at least 500 million accounts and attributed the attack to state-backed hackers. The disclosure triggered FBI scrutiny, political pressure, lawsuits, and concerns over Verizon's pending acquisition.
In 2016, after a hacker claimed to possess large amounts of Yahoo user data, Yahoo conducted a renewed review of the 2014 intrusion. That examination led the company to understand the breach more fully and prepare a public disclosure.
In 2014, Yahoo hired Alex Stamos as chief information security officer as part of a broader push to improve security, including encryption efforts. Former employees later said internal conflicts and resource constraints limited how far those changes went.
Around 2010, Yahoo was reportedly penetrated by Chinese military hackers, an early sign of the company's longstanding security challenges. The incident was cited later as evidence that Yahoo lagged peers in prioritizing defensive improvements.
In late 2014, attackers believed by Yahoo to be backed by a foreign government stole account data affecting more than 500 million users. Yahoo later said it detected signs of the intrusion shortly after it occurred but did not understand its full scope at the time.
In August 2013, attackers stole data associated with more than 1 billion Yahoo accounts, making it the largest known Yahoo breach disclosed at the time. Reports later said Yahoo was still using MD5 password hashing during this period.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
9 references tracked. Mallory keeps watching after this page renders.
theverge.com
Open sourcecbc.ca
Open sourceengadget.com
Open sourceweb.archive.org
Open sourcenytimes.com
Open sourcewashingtonpost.com
Open sourcenytimes.com
Open sourcebbc.co.uk
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.