logo

The Really Scary Detail You Overlooked in Yahoo’s Data Theft Statement

ID: f3a803b4-5d1d-582f-8080-d2eef878c809

STIX ID: report--f3a803b4-5d1d-582f-8080-d2eef878c809

Feed Name: Security Ledger

Threat Score
90/100

Date Published: 2016-12-15

Date Updated: 2026-05-08

Author: Paul Roberts

...
...

In brief: Yahoo disclosed a large-scale breach in which attackers—reported as state-sponsored—stole data on roughly one billion user accounts and proprietary code/secret used to generate authentication cookies, enabling the attackers to forge valid session cookies and impersonate users. The incident reflects deep, long-term access to Yahoo's internal systems and raises severe risks of account takeover and misuse of stolen data; Yahoo has invalidated forged cookies and recommended users enable multi-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.