Yahoo has admitted its email service was breached by a “co-ordinated effort”, and warned users their passwords may be reset.
The Internet giant’s Yahoo Mail systems was hit by attackers, according to a Yahoo advisory. “Security attacks are unfortunately becoming a more regular occurrence,” wrote Jay Rossiter, Yahoo’s vice president for platforms and personalisation products. “Recently, we identified a coordinated effort to gain unauthorised access to Yahoo Mail accounts. Upon discovery, we took immediate action to protect our users, prompting them to reset passwords on impacted accounts.”
“We have no evidence that they were obtained directly from Yahoo’s systems. Our ongoing investigation shows that malicious computer software used the list of usernames and passwords to access Yahoo Mail accounts. The information sought in the attack seems to be names and email addresses from the affected accounts’ most recent sent emails,” wrote Rossiter.
Yahoo said it was resetting the passwords on impacted accounts and it is using second sign-in verification to allow users to re-secure their accounts. It also said that it had implemented “additional measures” to safeguard Yahoo systems from future attacks.
The company said that those Yahoo Mail users who have been impacted by the attack, will be prompted to change their password and may receive an email notification or an SMS text if they have added a mobile number to their account.
Yahoo confirmed it is working with US federal law enforcement to find and prosecute the attackers.
“We regret this has happened and want to assure our users that we take the security of their data very seriously,” said Rossiter.
Earlier this month, thousands of visitors to the Yahoo.com website were hit by malicious ads, pointing them to downloads of the prevalent Magnitude exploit kit, which attempts to drop malware on victims’ machines. The company had earlier pledged to introduce encryption into all of its products, as well as internal communications, by March 2014.
But Yahoo remains a firm favourite of cyber attackers.
In July 2012, 450,000 Yahoo Voice passwords were posted online, an event made worse by the fact the company was storing passwords unencrypted. It was later sued by one of its users over the breach. Then in January 2013, it turned out a Yahoo attempt to cover a security hole in Yahoo mail had failed, leaving the door open to hackers hoping to take over a user account.
What do you know about Edward Snowden And The NSA? Take our quiz!
CMA receives 'provisional recommendation' from independent inquiry that Apple,Google mobile ecosystem needs investigation
Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…
Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…
Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector
Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…
Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…