World Wide Web

Yahoo Mail Hacked, User Passwords Stolen

By Michael Smith


January 31, 2014 10:03AM
Yahoo said it regrets that Yahoo Mail has been hacked and wants to assure Yahoo Mail users that the company takes the security of consumer data very seriously. In the wake of the hack on Yahoo Mail, the firm is urging users to adopt better password practices by changing their passwords regularly and using variations of symbols and characters.


Neustar, Inc. (NYSE: NSR) is a trusted, neutral provider of real-time information and analysis to the Internet, telecommunications, information services, financial services, retail, media and advertising sectors. Neustar applies its advanced, secure technologies in location, identification, and evaluation to help its customers promote and protect their businesses. More information is available at www.neustar.biz.


After major e-mail woes in December, Yahoo is now getting hit with another massive problem. Yahoo Mail has been hacked. Jay Rossiter, senior vice president of Platforms and Personalization Products at Yahoo, confirmed the hack on the firm’s Tumblr blog.“Security attacks are unfortunately becoming a more regular occurrence. Recently, we identified a coordinated effort to gain unauthorized access to Yahoo Mail accounts,” he said. “Upon discovery, we took immediate action to protect our users, prompting them to reset passwords on impacted accounts.”Based on Yahoo’s current findings, Rossiter said the list of usernames and passwords that were used to execute the attack was likely collected from a third-party database compromise.


What Is Yahoo Doing?

“We have no evidence that they were obtained directly from Yahoo’s systems. Our ongoing investigation shows that malicious computer software used the list of usernames and passwords to access Yahoo Mail accounts,” Rossiter said. “The information sought in the attack seems to be names and e-mail addresses from the affected accounts’ most recent sent e-mails.”

Rossiter then outlined what Yahoo is doing to protect Mail users. First, the company is resetting passwords on impacted accounts and using second sign-in verification to allow users to re-secure their accounts. Rossiter said impacted users will be prompted to change their passwords and may receive an e-mail notification or an SMS text if they have added a mobile number to their accounts.

Yahoo is also working with federal law enforcement to find and prosecute the perpetrators responsible for this attack. He said the company has implemented additional measures to block attacks against Yahoo’s systems.


Keeping E-mail Accounts Secure

“In addition to adopting better password practices by changing your password regularly and using different variations of symbols and characters, users should never use the same password on multiple sites or services,” Rossiter said. “Using the same password on multiple sites or services makes users particularly vulnerable to these types of attacks.”

Rossiter concluded by saying he regrets this has happened and wants to assure Yahoo Mail users that company takes the security of consumer data very seriously. In December, Yahoo CEO Marissa Mayer personally apologized for a Yahoo Mail outage: “This has been a very frustrating week for our users and we are very sorry.”

“We will continue to work on rolling out IMAP access and to fully restore inbox state (for example, which folders messages were placed in, which messages were starred, etc). This process differs for each user and as restoration continues, we’re committing to communicating directly with you on progress on an individual basis,” she said.

“Above all else, we’re going to be working hard on improvements to prevent issues like this in the future. While our overall uptime is well above 99.9%, even accounting for this incident, we really let you down this week,” she said at the time.

Michael Smith

Michael Smith is a seasoned technology writer with over 10 years of experience specializing in internet-related topics, emerging technologies, and digital trends. His deep understanding of the tech landscape allows him to simplify complex subjects for a wide range of readers, from industry professionals to tech enthusiasts. Michael has contributed to numerous well-regarded publications and has a proven track record of delivering accurate, engaging, and well-researched content. With a passion for innovation, Michael regularly covers topics such as cybersecurity, cloud computing, artificial intelligence, and internet infrastructure. His ability to stay ahead of the curve in this fast-paced field ensures that readers receive the latest insights and information on cutting-edge technologies. In addition to his writing career, Michael holds a degree in Computer Science.

Leave a Comment