• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • About
  • Structure
  • Schedule
    • First Half of the Semester
      • Week 1: Overview of Course
      • Week 2: TCP/IP and Network Architecture
      • Week 3: Reconnaissance
      • Week 4: Vulnerability scanning
      • Week 5: System and User enumeration
      • Week 6: Sniffers
      • Week 7: NetCat, Hellcat
    • Second Half of the Semester
      • Week 8: Social Engineering, Encoding, and Encryption
      • Week 9: Malware
      • Week 10: Web application hacking, Intercepting Proxies, and URL Editing
      • Week 11: SQL injection
      • Week 12: Web Services
      • Week 13: Evasion Techniques
      • Week 14: Review of all topics and wrap up discussion
  • Assignments
    • Analysis Reports
    • Quizzes & Tests
  • Webex
  • Harvard Coursepack
  • Gradebook

ITACS 5211: Introduction to Ethical Hacking

Wade Mackay

Yahoo Confirms 500 Million Accounts Were Hacked by ‘State Sponsored” Hackers

September 26, 2016 by Scott Radaszkiewicz 2 Comments

Article Link: http://thehackernews.com/2016/09/yahoo-data-breach.html

The following article discusses a data breach at Yahoo that happened back in 2014.  Account information for over 200 Million Yahoo accounts was being sold on the Dark Web.    An estimate claims that 500 Million accounts could have been effected. N credit card information was obtained, but user logins, passwords, security question answers and questions were stolen.

Yahoo claims that it was a state sponsored attack, but have not revealed any proof of that comment.

Yahoo users are urged to change their password.

In reviewing this article, it’s scary.   From the teen in the basement to the state sponsored hacker, there is so much to watch out for!   I think about my own life.  All the information that is put out there in things like Google Mail and Docs.    It’s scary to know that we can take the best precautions to protect our information, but once it leaves our hands, it’s out there.  We have no accountability for the safety of our information that we put out in Cyberspace!  But yet, we continue to do it more and more, at an alarming rate!

 

Filed Under: Uncategorized Tagged With:

Reader Interactions

Comments

  1. Loi Van Tran says

    September 27, 2016 at 10:40 am

    Thanks for the article Scott. You’re absolutely right about the information that we put on the internet is no longer ours and we are depending on the companies to protect it. As we seen over the years, attacks on corporate systems has plagued every industries. We’re talking about script kiddies to state-sponsored attacks. It is important to point out that even though Yahoo probably encrypted the data that was ex-filtrated, once the data is out of their control, the hacker can spend as much time as it takes to decrpyt the data.

    Although systems controls are out of the user’s hands, there are some additional security features that these type of companies provide. Some email services like Yahoo and Gmail also provide Two-factor authentication. Aside from entering your username and password, Yahoo would send you a text message with a verification code to enter along with the typical login credentials. So even if a hacker obtains your username and password, they will also need your phone.

    Log in to Reply
  2. Jason A Lindsley says

    September 27, 2016 at 10:49 pm

    I have a Yahoo account that I rarely use, but it still contains PII that I would not like leaked. Fortunately, I was using Yahoo’s one time password feature. It’s similar to two-factor authentication (i.e. password + SMS one time code), but you do not enter a password at all. Each time you try to login, you are e-mailed an 8 character one time password.

    Some would argue that two-factor authentication is stronger, however in this case the users that did not have a static password stored are fortunate because many people use the same or similar passwords for multiple accounts.

    There are multiple arguments to these security options. This article below outlines that SMS passwords could be targeted by Malware:

    http://www.darkreading.com/endpoint/yahoos-one-time-passwords-have-security-experts-divided/d/d-id/1319491

    In this case, I feel fortunate that my password was not stored and my account was not compromised, however it reiterates the importance of using alternative methods of authentication and complex passwords that are unique for all of your accounts.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (133)
  • Week 01: Overview (1)
  • Week 02: TCP/IP and Network Architecture (8)
  • Week 03: Reconnaisance (25)
  • Week 04: Vulnerability Scanning (19)
  • Week 05: System and User Enumeration (15)
  • Week 06: Sniffers (9)
  • Week 07: NetCat and HellCat (11)
  • Week 08: Social Engineering, Encoding and Encryption (12)
  • Week 09: Malware (14)
  • Week 10: Web Application Hacking (12)
  • Week 11: SQL Injection (11)
  • Week 12: Web Services (10)
  • Week 13: Evasion Techniques (7)
  • Week 14: Review of all topics (5)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in