← Case Files · The Breach Files
Yahoo, 2013–2014: three billion accounts, and three years of silence
- People affected
- 3 billion accounts
- When it happened
- August 2013 and late 2014
- Made public
- September and December 2016; revised to 3 billion in October 2017
- How they got in
- Spear-phishing an employee, then forged authentication cookies
- Attributed to
- Two FSB officers and two contracted hackers, indicted by the US Department of Justice in 2017
- What it cost
- $350 million cut from the Verizon sale price; $35 million SEC penalty; $117.5 million class settlement
What was exposed: Names · Email addresses · Phone numbers · Dates of birth · Hashed passwords (MD5 in the 2013 set) · Security questions and answers, some unencrypted
Yahoo holds a record that will be difficult to beat: it lost every account it had ever issued. Three billion of them, across two separate intrusions, disclosed three years after the fact and in the middle of selling the company. The size is the headline, but the instructive part is the silence — what a company does with the knowledge of a breach when the knowledge itself has become a liability.
What happened
There were two intrusions, and for a long time the public only knew about one.
In late 2014, attackers stole account data belonging to at least 500 million users. Yahoo's security team knew of that intrusion at the time; a small number of accounts were flagged, and senior management was informed. It was not disclosed publicly until 22 September 2016 — two months after Verizon had agreed to buy Yahoo's operating business for $4.83 billion.
Three months later, in December 2016, Yahoo announced a second and separate breach, from August 2013, involving a billion accounts. That figure held until October 2017, when Yahoo — by then absorbed into Verizon — confirmed that the 2013 intrusion had in fact touched every account in existence: three billion, including Flickr, Tumblr and Fantasy Sports users who had never thought of themselves as Yahoo customers at all.
How they got in
The 2014 intrusion began the way most do: a spear-phishing email that worked on one employee. From that foothold, the attackers reached two things that mattered far more than any individual mailbox.
The first was the User Database — the master record of accounts, containing names, email addresses, telephone numbers, dates of birth, hashed passwords and, critically, security questions and answers. The second was the Account Management Tool, Yahoo's internal administrative console.
Why the cookies matter more than the passwords. With access to the account management tooling, the attackers could mint their own authentication cookies — the tokens a browser holds that tell a server "this person has already logged in". A forged cookie bypasses the password entirely. It also survives a password change, which is the single piece of advice every breach notice gives. For the accounts targeted this way, the standard remediation did nothing at all; Yahoo had to invalidate the forged cookies centrally, which it did in 2016, years after they were created.
In March 2017 the US Department of Justice indicted four people: two officers of Russia's Federal Security Service, Dmitry Dokuchaev and Igor Sushchin, and two hackers they directed, Alexsey Belan and Karim Baratov. The indictment described a state intelligence service using criminal contractors — the officers wanted access to specific accounts belonging to journalists, officials and company executives, and the contractors monetised the rest of the database on the side. Baratov, arrested in Canada, pleaded guilty and was sentenced to five years in 2018. Belan, already on the FBI's most wanted list, remains at large.
The timeline
- August 2013 — The intrusion that ultimately touched all three billion accounts.
- Late 2014 — A second, separate intrusion; at least 500 million accounts taken. Yahoo's security staff identify it at the time.
- July 2016 — Verizon agrees to buy Yahoo's operating business for $4.83 billion.
- August 2016 — A hacker known as Peace advertises 200 million Yahoo accounts for sale, prompting an internal investigation.
- 22 September 2016 — Yahoo discloses the 2014 breach: 500 million accounts, attributed to a "state-sponsored actor".
- 14 December 2016 — Yahoo discloses the separate 2013 breach: one billion accounts.
- March 2017 — The DOJ indicts two FSB officers and two contracted hackers.
- June 2017 — The Verizon acquisition closes at roughly $4.48 billion, $350 million below the original price.
- 3 October 2017 — The 2013 figure is revised: all three billion accounts.
- April 2018 — The SEC fines Altaba $35 million for two years of non-disclosure to investors.
- 2019 — A $117.5 million class-action settlement is approved.
What was taken
Names, email addresses, telephone numbers, dates of birth, hashed passwords, and security questions and answers — some of the latter stored without encryption.
The password hashing is worth dwelling on. The 2013 set used MD5, an algorithm that was already understood to be unsuitable for password storage years before 2013; modern hardware can test billions of MD5 candidates per second, so any password that appears in a wordlist falls immediately. But the security answers are the more durable problem. A password can be changed in thirty seconds. The city where you were born cannot, and neither can your mother's maiden name — and both were, for years, accepted by banks and telecoms as proof that you were you.
What happened next
The commercial consequences were real but oddly indirect. The purchase price fell by $350 million and the two companies agreed to share certain liabilities. Yahoo's general counsel resigned; chief executive Marissa Mayer forfeited her annual bonus and equity award. The SEC's $35 million penalty in 2018 was the first time it had punished a company specifically for failing to tell investors about a data breach, and it landed not because Yahoo was breached but because Yahoo's own risk disclosures had continued to describe breaches as a hypothetical future risk while it knew about a real one.
For users, the practical result was three billion accounts' worth of email addresses, phone numbers and security answers circulating permanently, plus the discovery that a password change had never been enough against forged session tokens.
What it changed
Yahoo is the case that turned breach disclosure into a securities question. Before it, a late disclosure was a public-relations problem and perhaps a regulatory one. After it, the SEC had demonstrated that describing a known incident as a hypothetical risk in an investor filing is a misstatement in its own right — a line of reasoning that runs directly into the SEC's 2023 rules requiring disclosure of material cybersecurity incidents within four business days.
It also settled an argument inside the industry about session tokens. Invalidate sessions on password change; treat cookie-minting tooling as the crown jewel it is; make the internal admin console the hardest system in the building rather than the most convenient. All of that is now standard advice, and Yahoo is the worked example everyone points at.
If you had a Yahoo account
- Assume the account is compromised, even if you abandoned it. Old Yahoo addresses are still listed as the recovery address on other people's live accounts. An abandoned mailbox with a reused password is a route into everything it can reset.
- Change every security answer you have reused. Not just at Yahoo. If you ever answered "first school" the same way at a bank, that answer is in circulation. Where a site insists on security questions, treat the answer as a second password and store it in a password manager rather than telling the truth.
- Kill reused passwords first. The Yahoo dump has been folded into every credential collection since, which means it is tried automatically against other services — see how those aggregated lists are used.
- Move recovery to something you still control. Point the recovery address and phone number of your important accounts at a mailbox you actively read, and turn on two-factor authentication where it is offered.
Questions people ask
How many accounts were in the Yahoo breach?
Three billion — every account Yahoo had ever issued, including Flickr, Tumblr and Yahoo Fantasy accounts. The company first said 500 million, then a separate billion, then in October 2017 confirmed that the August 2013 intrusion had touched all three billion.
Were Yahoo passwords cracked?
Many of them, yes. The 2013 set used MD5, a hashing algorithm that was already considered unfit for passwords at the time and can be attacked at enormous speed on consumer graphics hardware. Worse, security questions and answers were taken too, and in some cases stored without encryption — and almost nobody changes their mother's maiden name after a breach.
What were the forged cookies?
The attackers obtained Yahoo's internal account management tooling and used it to mint authentication cookies — browser tokens that told Yahoo's servers a user had already logged in. A forged cookie bypasses the password entirely, so changing the password did not evict the intruder. Yahoo invalidated the forged cookies in 2016.
Did the breach affect the Verizon sale?
It cost $350 million. Verizon had agreed to buy Yahoo's operating business for $4.83 billion in July 2016; after the disclosures the price was renegotiated to roughly $4.48 billion, with the two companies splitting certain liabilities. The SEC later fined the remaining entity, Altaba, $35 million for failing to disclose the 2014 breach to investors for two years.
Sources
- US Securities and Exchange Commission order against Altaba (formerly Yahoo), April 2018
- US Department of Justice indictment of FSB officers and co-conspirators, March 2017
- Yahoo Inc. SEC filings and investor statements, 2016–2017
- In re Yahoo! Inc. Customer Data Security Breach Litigation — $117.5 million settlement, 2019
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.