Saturday, April 26, 2025
1:58 AM
Doha,Qatar
Yahoo

Yahoo pressed to explain huge 'state sponsored' hack

Yahoo faced pressure on Friday to explain how it sustained a massive cyber attack -- one of the biggest ever, and allegedly state-sponsored -- allowing hackers to steal data from half a billion users two years ago.
The US online giant said its probe concluded that "certain user account information was stolen" and that the attack came from "what it believes is a state-sponsored actor."
The comments come after a report earlier this year quoted a security researcher saying some 200mn accounts may have been accessed and that hacked data was being offered for sale online.
"Yahoo is working closely with law enforcement on this matter," said Yahoo, adding it believes data linked to at least 500mn user accounts was stolen -- in what could be the largest-ever breach for a single organisation.
Yahoo said the stolen information may have included names, email addresses, birth dates, and scrambled passwords, along with encrypted or unencrypted security questions and answers that could help hackers break into victims' other online accounts.
While there is no official record of the largest breaches, many analysts have called the Myspace hack revealed earlier this year as the largest to date, with 360mn users affected.
In 2014 a US firm specialised in discovering breaches said that a Russian group has hacked 1.2bn usernames and passwords belonging to more than 500mn email addresses.
The firm, Hold Security, gave no details of the companies affected by the hack.
Ammunition for hackers 
Computer security analyst Graham Cluley said the stolen Yahoo data "could be useful ammunition for any hacker attempting to break into Yahoo accounts, or interested in exploring whether users might have used the same security questions/answers to protect themselves elsewhere on the web."
He noted that while Yahoo said that it believes the hack was state-sponsored, the company provided no details regarding what makes them think that is the case.
"If I had to break the bad news that my company had been hacked... I would feel much happier saying that the attackers were 'state-sponsored,'" rather than teen hackers, Cluley said in a blog post.
University of Notre Dame associate teaching professor and data security specialist Timothy Carone told AFP that the Yahoo hack fit the "big picture" when it comes to cyberattacks launched by spy agencies in Russia, China, North Korea or other countries.
"It just smacks of traditional trade craft," Carone said.
Chinese hackers have been accused of everything from stealing corporate secrets to an enormous breach of US government personnel files that affected a staggering 21.5mn people and reportedly led Washington to pull its intelligence operatives out of China.
North Korea is known to operate an army of thousands of elite hackers accused of launching crippling cyber-attacks on South Korean organisations and officials over the years.
But it was the high-profile hacking attack on Sony Pictures in December 2014 that shed light on the growing threat of the North's hacking capability, although Pyongyang denied responsibility for the attacks.
It appeared that looted Yahoo data did not include unprotected passwords or information associated with payments or bank accounts, the Silicon Valley company said.
Yahoo is asking affected users to change passwords, and recommending anyone who has not done so since 2014 to take the same action as a precaution.
Users of Yahoo online services were urged to review accounts for suspicious activity and change passwords and security question information used to log in anywhere else if it matched that at Yahoo.
"Online intrusions and thefts by state-sponsored actors have become increasingly common across the technology industry," Yahoo said in a statement.
"Yahoo and other companies have launched programs to detect and notify users when a company strongly suspects that a state-sponsored actor has targeted an account."
Yahoo being bought 
Confirmation of the major cyber breach comes two months after Yahoo sealed a deal to sell its core internet business to telecom giant Verizon for $4.8bn, ending a two-decade run as an independent company.
It was not immediately clear if the data breach could impact the closing of the deal or the price agreed by Verizon.
"Frankly, the timing couldn't be worse for Yahoo," Cluley said.
The telecom firm said it was reviewing the new information.
"Within the last two days, we were notified of Yahoo's security incident," Verizon said in a statement.
"We will evaluate as the investigation continues through the lens of overall Verizon interests, including consumers, customers, shareholders and related communities."

Comments
  • There are no comments.

Add Comments

B1Details

Latest News

SPORT

Canada's youngsters set stage for new era

Saying goodbye is never easy, especially when you are saying farewell to those that have left a positive impression. That was the case earlier this month when Canada hosted Mexico in a friendly at BC Place stadium in Vancouver.

1:43 PM February 26 2017
TECHNOLOGY

A payment plan for universal education

Some 60mn primary-school-age children have no access to formal education

11:46 AM December 14 2016
CULTURE

10-man Lekhwiya leave it late to draw Rayyan 2-2

Lekhwiya’s El Arabi scores the equaliser after Tresor is sent off; Tabata, al-Harazi score for QSL champions

7:10 AM November 26 2016
ARABIA

Yemeni minister hopes 48-hour truce will be maintained

The Yemeni Minister of Tourism, Dr Mohamed Abdul Majid Qubati, yesterday expressed hope that the 48-hour ceasefire in Yemen declared by the Command of Coalition Forces on Saturday will be maintained in order to lift the siege imposed on Taz City and ease the entry of humanitarian aid to the besieged

10:30 AM November 27 2016
ARABIA

QM initiative aims to educate society on arts and heritage

Some 200 teachers from schools across the country attended Qatar Museum’s (QM) first ever Teachers Council at the Museum of Islamic Art (MIA) yesterday.

10:55 PM November 27 2016
ARABIA

Qatar, Indonesia to boost judicial ties

The Supreme Judiciary Council (SJC) of Qatar and the Indonesian Supreme Court (SCI) have signed a Memorandum of Understanding (MoU) on judicial co-operation, it was announced yesterday.

10:30 AM November 28 2016
ECONOMY

Sri Lanka eyes Qatar LNG to fuel power plants in ‘clean energy shift’

Sri Lanka is keen on importing liquefied natural gas (LNG) from Qatar as part of government policy to shift to clean energy, Minister of City Planning and Water Supply Rauff Hakeem has said.

10:25 AM November 12 2016
B2Details
C7Details