Yahoo confirms massive leak of 500 million user accounts

Uh oh, Yahoo.
By
Nicole Gallucci
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

Yahoo officially admitted Thursday that data from at least 500 million user accounts has been stolen, confirming one of the largest security breaches ever after years of speculation via a statement on its website.

Yahoo confirmed that user account information was stolen from the company’s network "in late 2014 by what it believes is a state-sponsored actor." The company suggests the stolen information could include personal credentials such names, email addresses, telephone numbers, dates of birth, hashed passwords (the vast majority with bcrypt) and even security questions and answers.

The ongoing investigation also revealed that unprotected passwords, payment card data and bank account information were not included in the stolen information, since that info isn't stored in the affected system. Yahoo stated that the company is working with law enforcement to further investigate the matter and has found no evidence that the state-sponsored actor is currently in its network.

Verizon, the company that acquired Yahoo's core business for $4.83 billion in July, released a statement saying that it had only learned of the breach "within the last two days," according to USA Today.

"We understand that Yahoo is conducting an active investigation of this matter, but we otherwise have limited information and understanding of the impact," Verizon said.

On Thursday morning, Recode reported that several sources involved with Yahoo said the company — which was recently purchased by Verizon for $4.83 — finally planned to address the data breach.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

According to Motherboard, the hacker, a known cybercriminal by the name of peace_of_mind, listed user credentials for 200 million Yahoo accounts on TheRealDeal, a marketplace on the dark web.

The credentials, including usernames, passwords and personal information were posted on the site for a price of $1,800.

Discussions of hacked Yahoo Mail usernames occurred back in 2014, and Motherboard reported that Yahoo acknowledged it was investigating the current data breach in the spotlight in August of this year.

In an August email, a Yahoo spokesperson told Motherboard, "We are aware of a claim ... We are committed to protecting the security of our users' information and we take any such claim very seriously.

"Our security team is working to determine the facts. Yahoo works hard to keep our users safe, and we always encourage our users to create strong passwords, or give up passwords altogether by using Yahoo Account Key, and use different passwords for different platforms."

Reports stated that in the past, the same hacker has been involved in selling illegally acquired information from MyspaceLinkedIn and Tumblr.

Mashable reached out to Yahoo for comment and will update this article once we receive a response.

Additional reporting by Jason Abbruzzese.

Mashable Image
Nicole Gallucci

Nicole is a Senior Editor at Mashable. She primarily covers entertainment and digital culture trends, and in her free time she can be found watching TV, sending voice notes, or going viral on Twitter for admiring knitwear. You can follow her on Twitter @nicolemichele5.


Recommended For You
Discord user data leak resurfaces on hacker forum as third-party service disputes breach
Discord logo


Yahoo's Vidya Nayak wants more women in tech
Yahoo executive Vidya Nayak

4 savvy finance accounts to follow on TikTok
money splayed out

Nintendo Switch 2 preorder date just days away, per leak
the new nintendo switch 2 on a glass display case

Trending on Mashable
NYT Connections hints today: Clues, answers for April 16, 2025
Connections game on a smartphone

Wordle today: Answer, hints for April 16, 2025
Wordle game on a smartphone

Deep sea craft filmed unprecedented footage of a colossal squid
An image from the first-ever confirmed footage of a colossal squid.

NYT Connections hints today: Clues, answers for April 15, 2025
Connections game on a smartphone

Lego is giving away Grogu models for free to celebrate Star Wars Day. Here’s how to get yours.
Lego Bricks in child's hands
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!