Yahoo thwarts web mail cyber attack
Internet giant claims to have prevented hackers from gaining access to users' Yahoo Mail accounts.
Yahoo claims to have thwarted a bid by hackers to gain unauthorised access to its users' email accounts.
The internet giant said in a blog post the list of user usernames and passwords needed to carry out the attack is likely to have been obtained from an attack on a third-party database.
"We have no evidence that they were obtained directly from Yahoo's systems," wrote Jay Rossiter, senior vice president of platforms and personalisation products at Yahoo.
The usernames and passwords were then used by "malicious software" to access people's accounts, according to Yahoo.
"The information sought in the attack seems to be names and email addresses from the affected accounts' most recent sent emails," the post continued.
The company said, upon discovering the attack, it took immediate action to protect affected users by sending out password reset prompts.
"We are resetting passwords on impacted accounts and we are using second sign-in verification to allow users to re-secure their accounts," the company said.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Impacted users will be prompted (if not, already) to change their password and may receive an email notification or an SMS text if they have added a mobile number to their account."
Furthermore, Yahoo said it is working with law enforcers to bring the people responsible for the attack to justice. It also moved to assure users that additional measures have been put in place to prevent further attacks on its systems.
"We regret this has happened and want to assure our users that we take the security of their data very seriously," the blog post concluded.
-
Global IT spending set to exceed $6 trillion in 2026News Several key areas are expected to drive the bulk of investment next year
-
Data engineers have never been more important, as businesses are starting to find outNews An MIT survey for Snowflake shows the changing role of data engineers – and their rise in influence
-
The worst hacks of all timeIn-depth Yahoo, LinkedIn, Facebook, here is a quick guide to some of the biggest data breaches in history
-
Yahoo handed £250,000 fine over 2014 data breach
News ICO punishes Yahoo's UK arm for failing to protect 515,000 Brits
-
Canadian pleads guilty to Yahoo hackNews Karim Baratov was paid by Russian security agents to break into Yahoo accounts in 2014
-
Russia denies it's responsible for Yahoo hackNews The Kremlin said there's "absolutely no question of any official involvement by any Russian agency"
-
Verizon knocks $350m off Yahoo dealNews Yahoo will also need to pay half of any liabilities incurred as a result of massive data breach
-
Yahoo email scandal could derail Safe Harbour replacementNews Reports of mass email surveillance prompt fears of rights infringements
-
Individual sues Yahoo over data breachNews New York man has accused Yahoo of gross negligence
-
Yahoo hack: what your business needs to know - and why you shouldn't panicAnalysis The Yahoo hack is frightening, but the worst of the attacks are likely already over