Yahoo Security Notice December 14, 2016

Yahoo has identified data security issues concerning certain Yahoo user accounts. Yahoo has taken steps to secure user accounts and is working closely with law enforcement.

Below are FAQs containing details about these issues and steps users can take to help protect their accounts.

For information about the data security issue the company disclosed on September 22, 2016, click here.

What happened?

Law enforcement provided Yahoo in November 2016 with data files that a third party claimed was Yahoo user data. We analyzed this data with the assistance of outside forensic experts and found that it appears to be Yahoo user data. Based on further analysis of this data by the forensic experts, we believe an unauthorized third party, in August 2013, stole data associated with more than one billion user accounts. Yahoo has not been able to identify the intrusion associated with this theft. We believe this incident is likely distinct from the incident we disclosed on September 22, 2016. We are notifying potentially affected users and have taken steps to secure their accounts, including requiring users to change their passwords. Yahoo has also invalidated unencrypted security questions and answers so that they cannot be used to access an account.

Separately, our outside forensic experts have been investigating the creation of forged cookies that could allow an intruder to access users’ accounts without a password. Based on the ongoing investigation, the outside forensic experts have identified user accounts for which they believe forged cookies were taken or used in 2015 or 2016. The company is notifying the affected account holders, and has invalidated the forged cookies. We have connected some of this activity to the same state-sponsored actor believed to be responsible for the data theft we disclosed on September 22, 2016.

Was my account affected by the August 2013 incident?

We are notifying potentially affected users and posting additional information on our website. Additionally, we are taking steps to secure users’ accounts, including requiring users to change their passwords. Yahoo has also invalidated unencrypted security questions and answers so that they cannot be used to access an account.

Was my account affected by the cookie forging activity?

Based on the ongoing investigation, the outside forensic experts have identified user accounts for which they believe forged cookies were taken or used in 2015 or 2016. The company is notifying the affected account holders, and has invalidated the forged cookies.

What information was taken in the August 2013 incident?

For potentially affected accounts, the stolen user account information may have included names, email addresses, telephone numbers, dates of birth, hashed passwords (using MD5) and, in some cases, encrypted or unencrypted security questions and answers. The investigation indicates that the stolen information did not include passwords in clear text, payment card data, or bank account information. Payment card data and bank account information are not stored in the system the company believes was affected.

What is a "hashed" password?

Hashing is a one-way mathematical function that converts an original string of data into a seemingly random string of characters. As such, passwords that have been hashed can’t be reversed into the original plain text password. At the time of the August 2013 incident, we used MD5 to hash passwords. We began upgrading our password protection to bcrypt in the summer of 2013. Bcrypt is a password hashing mechanism that incorporates security features, including salting and multiple rounds of computation, to provide advanced protection against password cracking.

What information was affected by the cookie forging activity?

Forged cookies could allow an intruder to access users’ accounts without a password. Based on an ongoing Yahoo investigation, we believe an unauthorized third party accessed our proprietary code to learn how to forge cookies. The outside forensic experts have identified user accounts for which they believe forged cookies were taken or used. The company is notifying the affected account holders, and has invalidated the forged cookies.

What is a “cookie”?

A cookie is a small piece of information stored on a computer for the purpose of identifying a web browser during interaction on websites. Websites use cookies to remember and recognize details about visitors, such as website preferences. Click here for more information on Yahoo practices regarding cookies and similar technologies.

Are these incidents related to the data theft that Yahoo announced on September 22, 2016?

We believe that the August 2013 incident is likely distinct from the incident we disclosed on September 22, 2016.

We have connected some of the cookie forging activity to the same state-sponsored actor believed to be responsible for the data theft we disclosed on September 22, 2016. Those users targeted by the state-sponsored actor were sent an additional notification like the one found here.

I think I received one or more emails about these issue. How do I know that they're really from Yahoo?

Click here to view the content of our notice to affected users. Please note that the emails from Yahoo about this issue will display the Yahoo Purple Y icon icon when viewed through the Yahoo website or Yahoo Mail app. Importantly, the emails do not ask you to click on any links or contain attachments and does not request your personal information. If an email you received about these issues prompts you to click on any links, download an attachment, or asks you for information, the email was not sent by Yahoo and may be an attempt to steal your personal information. Avoid clicking on links or downloading attachments from such suspicious emails.

What is Yahoo doing to protect my account?

We have taken action to protect our users, including:

  • We are requiring potentially affected users to change their passwords.
  • We invalidated unencrypted security questions and answers so that they cannot be used to access an account.
  • We invalidated the forged cookies and hardened our systems to secure them against similar attacks.
  • We continuously enhance our safeguards and systems that detect and prevent unauthorized access to user accounts.

How do I change my password or disable security questions and answers?

You can change your Yahoo password or security questions and answers by clicking here. We are requiring potentially affected users to change their passwords, and we have invalidated unencrypted security questions and answers so that they cannot be used to access an account.

Is there anything I can do to protect myself?

We encourage all of our users to follow these security recommendations:

  • Change your password and security questions and answers for any other accounts on which you use the same or similar information used for your Yahoo Account.
  • Review all of your accounts for suspicious activity.
  • Be cautious of any unsolicited communications that ask for your personal information or refer you to a web page asking for personal information.
  • Avoid clicking on links or downloading attachments from suspicious emails.

Additionally, please consider using Yahoo’s Account Key, a simple authentication tool that eliminates the need to use a password on Yahoo altogether.

Are Tumblr accounts affected?

No. The systems from which the data was stolen in August 2013 contained no Tumblr user data at the time of the theft. Additionally, Yahoo has no indication that the forged cookies were used to access Tumblr accounts.

How can I get help with my account?

If you need further information or assistance with your account, please visit https://nz.help.yahoo.com, where you will find the latest information and may be able to access direct customer support. DO NOT ENGAGE with any support service other than those provided by Yahoo, particularly support service providers that charge a fee for their service. Yahoo does not charge for support service for its accounts. Please note that Yahoo channels all support through https://nz.help.yahoo.com.