Yahoo confirms theft of 450,000 users' passwords (Update)

Jul 12, 2012 by RAPHAEL SATTER

Some 450,000 Yahoo users' email addresses and passwords have been leaked because of a security breach, the company confirmed Thursday, adding that just a small fraction of the stolen passwords were valid.

The company said in a statement that an "old file" from the Yahoo Contributor Network was compromised Wednesday. Among the stolen emails and passwords were many from Yahoo's own email service along with those of other companies. The Yahoo Contributor Network is a content-sharing platform.

Yahoo said it is fixing the vulnerability that led to the disclosure, changing the passwords of affected Yahoo users, and notifying other companies whose users' accounts may have been compromised.

"We apologize to all affected users," the company statement said.

Technology news websites including CNET, Ars Technica, and Mashable identified the hackers behind the attack as a little-known outfit calling itself the D33D Company. The group was quoted as saying it had stolen the unencrypted passwords using an SQL injection — the name given to a commonly used attack in which hackers use rogue commands to extract data from vulnerable websites.

"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call," the group was quoted as saying.

Online security experts said Yahoo might have done more to protect the stored passwords, with Ohio-based TrustedSec describing the Internet giant's decision not to encrypt them as "most alarming."

Nevertheless, the haul does not appear as useful to hackers as they might have thought. Yahoo cautioned that only 5 percent of passwords associated with its account holders were valid.

It was not immediately possible to contact the Ukraine-registered website associated with D33D Company. Its contact form was inoperable Thursday, while an email address and a phone number attributed to the site's registrant appeared to be invalid.

Explore further: Password breach spreads beyond LinkedIn

4.5 /5 (2 votes)
add to favorites email to friend print save as pdf

Related Stories

Hacker claims porn site users compromised

Feb 13, 2012

A hacker claims to have compromised the personal information of more than 350,000 users after breaking into a disused website operated by pornography provider Brazzers.

Spotlight falls on Sony's troubled cybersecurity

Jun 03, 2011

(AP) -- Another massive data breach at Sony has left hackers exulting, customers steaming and security experts questioning why basic fixes haven't been made to the company's stricken cybersecurity program.

Hackers claim new Sony cyberattack

Jun 03, 2011

Hackers have claimed to have compromised more than one million passwords, email addresses and other information from SonyPictures.com in the latest cyberattack on the Japanese electronics giant.

Password breach spreads beyond LinkedIn

Jun 07, 2012

More websites admitted security breaches Thursday after LinkedIn said some of its members' passwords were stolen, and experts warned of email scams targeting users of the social network. ...

Recommended for you

Facebook joins Web freedom group

5 hours ago

Facebook on Wednesday became a full member of the Global Network Initiative, a non-governmental organization promoting Internet freedom and privacy rights.

Big Data—for better or worse

9 hours ago

A full 90% of all the data in the world has been generated over the last two years. The internet companies are awash with data that can be grouped and utilised. Is this a good thing?

Risky behaviour starts young on social media: survey

11 hours ago

Australian children are accessing social media websites at an increasingly younger age, a new survey suggests, with one in five "tweens" admitting they have chatted to someone online they do not know.

Poll: Teens migrating to Twitter (Update)

May 21, 2013

Twitter is booming as a social media destination for teenagers who complain about too many adults and too much drama on Facebook, according to a new study published Tuesday about online behavior. It said ...

User comments : 0

More news stories

NASA: Austin, calling Austin. 3-D pizzas to go

(Phys.org) —The idea of living with 3-D printed food is neither unthinkable nor new; designers and futurists have been looking to 3-D printing as food's next frontier. In 2012, there was news that the Thiel ...

Forecast for Titan: Wild weather could be ahead

(Phys.org) —Saturn's moon Titan might be in for some wild weather as it heads into its spring and summer, if two new models are correct. Scientists think that as the seasons change in Titan's northern hemisphere, ...