Yahoo to confirm data breach

Yakk

Golden Member
May 28, 2016
1,574
275
81
Worst kept secret... LOL... everyone I know who used yahoo mail had to stop using it because of the amount of garbage going on there...
 

John Connor

Lifer
Nov 30, 2012
22,757
617
121
This means E-mail passwords are at peril, correct? I just changed my E-mail passwords. One account uses 2FA.
 

quikah

Diamond Member
Apr 7, 2003
4,104
672
126
Interesting, a few years ago when I was still using yahoo messenger I got an IM from my spam email account (the account use for signups). It was weird. Wonder if this was why. I had changed the password on it.
 

Ns1

No Lifer
Jun 17, 2001
55,418
1,599
126
wow...

The stolen data includes users' names, email addresses, telephone numbers, dates of birth, hashed passwords and security questions for verifying an account holder's identity.
 

Imp

Lifer
Feb 8, 2000
18,828
184
106
Didn't they already announce this years ago?

Closed all my Yahoos last year. It remains the only email of mine that got hacked and sent spam to my contacts.
 

Yakk

Golden Member
May 28, 2016
1,574
275
81
Didn't they already announce this years ago?

Closed all my Yahoos last year. It remains the only email of mine that got hacked and sent spam to my contacts.

Yeah, I had the same thing happen 4 years ago when I left yahoo. Seems they are continously being hacked, but don't announce it. I'd warned my customers and friends to close their accounts years ago, most did. The ones that didn't all had the same spam email hack to contacts.
 

Six

Senior member
Feb 29, 2000
523
34
91
Now's as good as time as ever. https://www.leakedsource.com/main

Just learned webhostingtalk got hacked.

Just tried that, and this was the result:

  • MySpace.com has: 1 result(s) found. This data was hacked on approximately 2013-06-11 What is in this database?

  • VerticalScope Network (Vbulletin) (939 Websites) has: 1 result(s) found. This data was hacked on approximately 2016-02-01 What is in this database?

  • Anandtech.com has: 1 result(s) found. This data was hacked on approximately 2016-03-15 What is in this database?
D'OH!
 

JEDI

Lifer
Sep 25, 2001
29,391
2,736
126
Just tried that, and this was the result:

  • MySpace.com has: 1 result(s) found. This data was hacked on approximately 2013-06-11 What is in this database?

  • VerticalScope Network (Vbulletin) (939 Websites) has: 1 result(s) found. This data was hacked on approximately 2016-02-01 What is in this database?

  • Anandtech.com has: 1 result(s) found. This data was hacked on approximately 2016-03-15 What is in this database?
D'OH!
an acct I rarely use:
VerticalScope Network (Vbulletin) (939 Websites) has: 1 result(s) found. This data was hacked on approximately 2016-02-01

ok, how do I find out which of the 939 websites that use Vbulletin was hacked?
(Not Anandtech since I didn't use that email for a 2nd acct here.)
 

Miramonti

Lifer
Aug 26, 2000
28,651
100
91
Just tried that, and this was the result:


  • Anandtech.com has: 1 result(s) found. This data was hacked on approximately 2016-03-15 What is in this database?
D'OH!
An email of mine came up in a database hacked just one day before AT's, and that was for Sysopt.com, the forum I frequented before jumping to AT 16 years ago. They must have been sweeping vBulletins everywhere that week.
 

Red Squirrel

No Lifer
May 24, 2003
68,459
12,613
126
www.anyf.ca
It's ridiculous how companies simply don't care about security, there's so many breaches these days it's ridiculous. There needs to be more liability for this when it comes to other people's info being kept on file. Companies should need to be held liable, and have to be compliant to some kind of standard, and get audited regularly etc. It's just getting ridiculous. The victim in these cases is the people. The corporations just write it off as a loss and move on, and the insurance covers liability. They have zero reason to care about security. Cheaper to deal with the fallout than to have preventative maintenance.

That said, I don't believe yahoo has any of my info. I may have signed up to something Yahoo related at some point though but can't think of anything off the top of my head. The issue though is that companies sell each other's info all the time. (that is something that should be illegal) So just because you never signed up directly to a company's service does not mean they don't have your info.
 

Skeeedunt

Platinum Member
Oct 7, 2005
2,777
3
76
One time I tried to install Java and ended up with all my search engines redirected to Yahoo! and I've been angry ever since.
 

John Connor

Lifer
Nov 30, 2012
22,757
617
121
Got an E-mail from Yahoo.

Dear _____,
We are writing to inform you about a data security issue that may involve your Yahoo account information.


What Happened?

A copy of certain user account information was stolen from our systems in late 2014 by what we believe is a state-sponsored actor. We are closely coordinating with law enforcement on this matter and working diligently to protect you.


What Information Was Involved?
The stolen user account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt) and, in some cases, encrypted or unencrypted security questions and answers. Not all of these data elements may have been present for your account. The ongoing investigation suggests that stolen information did not include unprotected passwords, payment card data, or bank account information; payment card data and bank account information are not stored in the system that the investigation found to be affected.


What We Are Doing

We are taking action to protect our users:

We are asking potentially affected users to promptly change their passwords and adopt alternate means of account verification.

We invalidated unencrypted security questions and answers so they cannot be used to access an account.

We are recommending that all users who haven't changed their passwords since 2014 do so.

We continue to enhance our systems that detect and prevent unauthorized access to user accounts.

We are working closely with law enforcement on this matter.


Our investigation into this matter continues.


What You Can Do

We encourage you to follow these security recommendations:

Change your password and security questions for any other accounts on which you used the same or similar information used for your Yahoo account.

Review your accounts for suspicious activity.

Be cautious of any unsolicited communications that ask for your personal information or refer you to a web page asking for personal information.

Avoid clicking on links or downloading attachments from suspicious emails.


Additionally, please consider using Yahoo Account Key, a simple authentication tool that eliminates the need to use a password altogether.


For More Information

For more information about this issue and our security resources, please visit the Yahoo Security Issue FAQs page available at https://yahoo.com/security-update.


Protecting your information is important to us and we work continuously to strengthen our defenses against the threats targeting our industry.

Sincerely,
Bob Lord
Chief Information Security Officer
Yahoo
 

Elixer

Lifer
May 7, 2002
10,371
762
126
No biggie. Used a fake name, contact info, and bday. And I never use that password for anything else. I created the acct to set up and alt FB account to test FB privacy settings.
This is pretty much what I do as well, I used fake info, dunno why anyone would use their real information on any site.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |