Tech Time Warp: Lessons learned from the Yahoo breaches of the early 2010s

Ten years ago, Yahoo announced a massive security breach—the largest of its time. Account information for 500 million Yahoo users had been stolen in a hybrid state-sponsored and criminal hacker attack.

When cyber espionage reached Yahoo

The details sound straight out of Hollywood: Two officers from the FSB, the Russian Federation’s counterintelligence service, had hired hackers to gain access to Yahoo user accounts (including one known to be on the FBI’s Cyber Most Wanted list, with an Interpol Red Notice for immediate detention attached to his name). Although their primary targets were Russian journalists, U.S. and Russian government officials, and significant individuals from the private sector, along the way the hackers compromised an estimated 500 million accounts. One of the hackers also made some cash, stealing at least 30 million accounts for a spam campaign, manipulating search engine traffic to make commissions, and stealing credit card and gift card numbers. News reports surfaced about the lack of prioritization of security at Yahoo vs. user experience and search.

It’s all bad. But then came more bad news. In December 2016, the company disclosed another breach, this one from 2013, in which more than 1 billion accounts were compromised. After that disclosure, the company forced all Yahoo users to change their passwords.

The real damage came after the breach

But it didn’t end there. On April 24, 2018, the Securities and Exchange Commission (SEC) announced Yahoo, now known as Altaba, would pay a $35 million penalty for the breach announced in 2016. In the press release, the SEC stated that “within days of the December 2014 intrusion,” the Yahoo security team had known of the hack, but the company had failed to properly investigate it, and also it had not disclosed the breach to investors for two years — when doing so became necessary as part of an acquisition by Verizon.

The takeaways here are clear: A hack is bad. Failure to properly investigate, respond to, and disclose it only compounds the damage.

Did you enjoy this installation of SmarterMSP’s Tech Time Warp? Check out others here.

Photo: Andrii Yalanskyi / Shutterstock

This post originally appeared on Smarter MSP.