Yahoo ‘Aware’ Of Data Breach Claim

Yahoo has confirmed it is “aware” of claims that leaked data on about 200 million of its accounts is being offered for sale, but declined to confirm or deny the legitimacy of the data.

The data went up for sale on the black market website The Real Deal on Monday, listed by an individual or group using the pseudonym “Peace” – the same who previously sold massive data caches stolen from social media services LinkedIn and MySpace.

‘Working to determine the facts’

Yahoo said in a statement it is “aware of a claim” and said its security team is “working to determine the facts”.

The data contains usernames, passwords protected by the MD5 encryption algorithm, dates of birth and in some cases back-up email addresses, according to the marketplace listing, and is offered for 3 Bitcoins, or around £1,400.

The records “most likely” date from 2012, according to the listing.

The user data from previous breaches, particularly the LinkedIn user information, has been linked to attacks on users’ accounts with other services where the same password was reused.

“We always encourage our users to create strong passwords, or give up passwords altogether by using Yahoo Account Key, and use different passwords for different platforms,” Yahoo stated.

Russian hackers

Peace claimed in an interview with Wired to have been part of a Russian hacking group that targeted technology firms.

The data caches from MySpace, LinkedIn and other services, all of which are several years old, began to appear after the group disbanded, according to reports.

Peace told technology news site Motherboard that like those caches, the Yahoo data had previously been provided to select individuals before going on sale.

The breaches previously linked to Peace include 160 million LinkedIn accounts, 100 million from Russian social media site VK and 360 million from MySpace.

Are you a security pro? Try our quiz!

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Anthropic Did Not Violate Authors’ Copyright, Judge Rules

Judge rules claim by authors that Anthropic had used their books to train Claude chatbot,…

9 hours ago

OpenAI Removes Mention Of Jony Ive Partnership After Trademark Dispute

Trademark dispute sees OpenAI removing mention of AI deal with legendary Apple designer Sir Jony…

11 hours ago

Waymo Partners Uber To Launch Atlanta Robotaxi Service

Ride-hailing service from Uber and Waymo launched in Atlanta, as Alphabet unit increases robotaxi expansion…

12 hours ago

UK May Compel Google To Change Search Rankings, Offer Alternatives

Competition regulator lays out roadmap to make search engine market “more open, competitive and innovative”

16 hours ago

Amazon Launches Second Batch Of Project Kuiper Satellites

Second batch of Kuiper internet satellites launched from Florida, as Amazon builds rival to Elon…

18 hours ago