01Summary
The Yahoo data breaches occurred in two major phases, compromising the accounts of roughly three billion users. The stolen data included personally identifiable information (PII) such as names, email addresses, phone numbers, and dates of birth, alongside hashed passwords and security questions. The attackers utilized sophisticated methods, including forging 'cookies' to bypass standard password authentication. The subsequent investigation revealed that the 2014 breach was specifically used for state espionage, targeting high-profile individuals, including US government officials and Russian journalists. The massive scale of the leak led to significant corporate fallout, notably reducing the price Verizon paid for Yahoo by $350 million.
02Background
Yahoo! Inc. was a major internet portal and technology company, making its user database an extremely valuable target for state-level actors. The sheer volume of data—three billion accounts—made it a prime asset for intelligence agencies seeking comprehensive profiles on global citizens and political figures.
03Key revelations
- 01The scale of the breach, affecting three billion accounts, was unprecedented.
- 02The data was used for state-sponsored espionage, targeting political and journalistic figures.
- 03The breach exposed hashed passwords and security questions, enabling sophisticated account takeover methods.
04Technical analysis
The attackers gained access to the core user database, exfiltrating records containing hashed passwords and associated PII. The use of cookie forging suggests a deep understanding of Yahoo's authentication protocols, allowing access without needing to crack the password hashes directly. The data was packaged for large-scale exfiltration, indicating a sustained, professional operation.
- Attack vector
- Database compromise / Internal system vulnerability
- Attack method
- Credential Theft and Data Exfiltration
- Initial access
- Compromised internal credentials or system vulnerability
- Lateral movement
- Internal network access to core user databases
- Exfiltration
- Bulk data transfer (exfiltration)
- Malware type
- Stealer
Vulnerabilities exploited
- Database Access Vulnerability
MITRE ATT&CK techniques
- T1537
05Threat actor
The perpetrators are attributed to state-sponsored actors, specifically linked to the Russian FSB. Their profile suggests a highly resourced, intelligence-driven operation focused on geopolitical espionage rather than simple financial gain.
Aliases
- Russian FSB Officers
- State Actors
APT designations
- APT28
MITRE groups
- T1113
Known members
- Karim Baratov
Attribution sources
- FBI
- Media Reports
06Victims and impact
Additional victims
- US Government Officials
- Russian Journalists
Countries affected
- United States
- Russia
07Data exposed
Data types
- names
- email addresses
- phone numbers
- dates of birth
- hashed passwords
- security questions
- PII
Notable documents
- Yahoo User Database Dump (2013)
- Yahoo User Database Dump (2014)
08Financial damage
The revelation of the breach was cited as reducing the purchase price of Yahoo by Verizon by $350 million.
09Timeline
- 2013-08-01Initial discovery and start of the first major data breach phase.
- 2014-09-01Completion of the second major data breach phase, compromising the remaining accounts.
- 2017-09-19Yahoo officially disclosed the full scope and scale of the data breaches to the public.
10Key figures
- Karim BaratovAttributed Perpetrator · FSBRussianAttribution only; no public legal outcome.
11On the record
The largest data breach in history, affecting all 3 billion Yahoo user accounts.
12Reaction and fallout
Public reaction
The public reaction was characterized by widespread alarm regarding the vulnerability of personal data held by major corporations. It spurred increased public awareness regarding the necessity of strong, multi-factor authentication methods.
Political impact
The breach fueled international debate regarding the security of private data held by US tech companies and the extent of foreign state surveillance capabilities. It heightened scrutiny on the security practices of major internet platforms.
Geopolitical consequences
The leak was explicitly used for state espionage, demonstrating the capability of Russian intelligence services to acquire and weaponize vast amounts of personal data against foreign political and journalistic targets.
13Legal
While Yahoo faced massive class-action lawsuits, the primary legal fallout was financial, impacting its valuation during the Verizon acquisition. Regulatory bodies increased scrutiny of data handling practices.
Civil lawsuits
- Class-action lawsuits filed by affected users (details vary by jurisdiction)
14Aftermath
Policy changes
- Increased industry focus on mandatory multi-factor authentication (MFA)
- Stricter regulatory requirements for data breach disclosure (e.g., GDPR influence)
Regulatory changes
- Increased scrutiny from US and EU regulators regarding data retention and security standards
Security improvements
- Mandatory implementation of MFA across major online services
- Adoption of stronger hashing algorithms (e.g., bcrypt, Argon2) for passwords
15Significance and legacy
Significance
This incident set a new benchmark for the scale of data compromise, demonstrating that even the most massive, seemingly secure corporate databases could be breached by sophisticated state actors. It highlighted the critical vulnerability of centralized PII storage and the weaponization of personal data for geopolitical ends.
Legacy
The Yahoo breaches contributed significantly to the global conversation around data sovereignty and the necessity of end-to-end encryption. It accelerated the industry shift toward decentralized identity management and mandatory MFA adoption.
16Disclosure and media
- Authentication
- Forensic analysis of leaked data structures
Media partners
- The New York Times
- Reuters
- BBC
Publishing organisations
- Investigative Journalists
- Security Researchers
18Field notes
- 01The breach was so massive that it affected users across nearly every country in the world.
- 02The attackers were reportedly interested in using the data to profile and target specific political dissidents and journalists.
19Resolution
Yahoo eventually disclosed the full scope of the breach in 2017, leading to significant financial and reputational damage, but no criminal charges were filed against the state actors involved.
20Sources
Official documents
- Verizon-Yahoo Acquisition Reports
References
- [1]FBI Reports on Foreign Espionage
- [2]Major Tech News Outlets Reporting on Yahoo Breach









