Skip to main content

SO YAHOO WAS HACKED IN 2014!


Image result for YAHOO MAIL HACKED

Yahoo has confirmed that hackers have stolen the personal information of at least 500 million of its accounts accounts over the past two years after a security breach in 2014.
“A recent investigation by Yahoo has confirmed that a copy of certain user account information was stolen from the company’s network in late 2014 by what it believes is a state-sponsored actor,” said Bob Lors Yahoo’s CISO.
“The account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt) and, in some cases, encrypted or unencrypted security questions and answers.
“The ongoing investigation suggests that stolen information did not include unprotected passwords, payment card data, or bank account information; payment card data and bank account information are not stored in the system that the investigation has found to be affected.”

So far Yahoo said its investigation does not point at the hack being once carried out be a state-sponsored actor but Lors said the company is still looking into the breach with the assistance of law enforcement.
While this goes on, Yahoo said it will be notifying potentially affected user and prompting them to change their passwords, as well as invalidate unencrypted security questions.
The company noted it is also working on enhancing its security systems to better detect and prevent unauthorised access to user’s accounts.
“Through strategic proactive detection initiatives and active response to unauthorised access of accounts, Yahoo will continue to strive to stay ahead of these ever-evolving online threats and to keep our users and our platforms secure,” Lors promised.

For Yahoo, the timing of the leaked data could not be worse as it is currently in the process of being bought by Verizon for £3.7 billion.

Comments

  1. Yahoo might lose so many users to its competitors unless something drastic is done to re-assure its millions of users

    ReplyDelete

Post a Comment

Popular posts from this blog

Top 20 Most Asked Third Party Risk Questions for Vendors  These questions help organizations assess the overall risk posed by third-party vendors, covering critical areas like data protection, regulatory compliance, and incident response. Here’s a list of the Top 20 Most Asked Third-Party Risk Management (TPRM) Questions for Vendors in TPRM questionnaires: 1. What types of sensitive data do you handle for our organization? Vendors should clarify the types of data they collect, process, or store, such as personal information, financial data, or intellectual property. 2. How do you protect data at rest and in transit? This question probes into the encryption methods, protocols, and security controls in place for safeguarding data during storage and transmission. 3. Do you have a formal Information Security Program in place? Vendors should describe their overall cybersecurity framework, including policies, procedures, and governance. 4. How do you manage user access to our data and s...
MY PEOPLE PLEASE I NEED YOUR ADVICE   Robbers enter a house, asks for all the money and valuables. After they collect what they can, they give the man of the house a gun with instructions to shoot his wife or else he be shot himself. The man gets the gun, points it at his wife and hesitates. He is thinking of what he has gone through in life with his wife and how she has suffered and sacrificed for him. He hands back the gun and says, “I am sorry I can’t do this… “The boss of the robbers silently grabs the gun from him and passes it on to the wife with the same instruction. The wife gets the gun and without any single hesitation points to her husband’s head and pulls the trigger. But alas, the gun had no bullets in it. The robbers get their gun and walk out of the house laughing. QUESTIONS FOR DISCUSSION 1. If you were the man in that house how would you react towards your wife? 2. If you were the wife, what explanation can you...

Microsoft Warns of Data Stealing Malware That Pretends to Be Ransomware

  Thursday - Microsoft warned of a "massive email campaign" that's pushing a Java-based STRRAT malware to steal confidential data from infected systems while disguising itself as a ransomware infection. "This RAT is infamous for its ransomware-like behavior of appending the file name extension .crimson to files without actually encrypting them," the Microsoft Security Intelligence team  said  in a series of tweets. The new wave of attacks, which the company spotted last week, commences with spam emails sent from compromised email accounts with "Outgoing Payments" in the subject line, luring the recipients into opening malicious PDF documents that claim to be remittances, but in reality, connect to a rogue domain to download the STRRAT malware. Besides establishing connections to a command-and-control server during execution, the malware comes with a range of features that allow it to collect browser passwords, log keystrokes, and run remote commands an...