Yahoo suffered two separate data breaches - the largest in history at the time of their disclosure - that together resulted in the theft of data from all 3 billion Yahoo user accounts. The first breach occurred in 2013; the second in 2014. Yahoo disclosed the 2014 breach in September 2016, nearly two years after it occurred. Yahoo disclosed the 2013 breach in December 2016, more than three years after it occurred. The delayed disclosures, combined with the unprecedented scale, made the Yahoo breaches a landmark case for both cybersecurity incident response and the governance failures that allowed breaches of this magnitude to go undetected and undisclosed for years.
The timing of the disclosures was not coincidental. Yahoo was in the process of selling itself to Verizon for $4.83 billion when the breaches were revealed. The disclosures triggered renegotiation of the deal, which ultimately closed at $4.48 billion - a $350 million reduction attributed to the breach liability. It was the first major case where a cybersecurity breach materially impacted an M&A transaction, and it made breach disclosure a mandatory due diligence item in every technology M&A deal that followed.
The 2014 Breach: State-Sponsored Hackers
The 2014 breach was attributed by the FBI and DOJ to four individuals: two officers of the Russian FSB (Federal Security Service) and two criminal hackers working with them. In March 2017, the DOJ indicted Dmitry Dokuchaev and Igor Sushchin (FSB officers), Alexsey Belan (a career criminal hacker on the FBI's Cyber Most Wanted list), and Karim Baratov (a Canadian-Kazakh freelance hacker). The indictment alleged that the FSB officers directed Belan and Baratov to use stolen Yahoo account credentials to access accounts of interest to Russian intelligence - including those of Russian journalists, US government officials, Russian opposition figures, and a Swiss bitcoin wallet service.
The 2014 breach used spear-phishing to obtain access to Yahoo's corporate network, where the attackers compromised the Yahoo Account Management Tool - an internal system that allowed Yahoo employees to access and manage user accounts. With this tool, they were able to create forged authentication cookies (called "nonces") that allowed them to access any Yahoo account without knowing the password. They also stole Yahoo's user database, which contained username, email address, phone number, date of birth, hashed passwords (using MD5 - a cryptographically broken hash function), and security questions and answers (encrypted with bcrypt in some accounts, stored in plaintext in others).
The use of MD5 for password hashing was a significant aggravating factor. MD5 produces hashes that can be cracked with GPU-accelerated dictionary attacks in seconds to minutes for common passwords. The stolen Yahoo password database was effectively a partially cracked credential database for anyone who obtained it. Given that password reuse across services was (and remains) common, many of the stolen Yahoo credentials would have been valid for other accounts.
The 2013 Breach: All 3 Billion Accounts
The 2013 breach was initially disclosed in December 2016 as affecting "more than 1 billion" accounts. In October 2017, after Verizon had completed the Yahoo acquisition (rebranded as Oath), new forensic analysis revealed that the 2013 breach had actually affected all 3 billion Yahoo accounts that existed at the time - the largest data breach in history by account count. The data stolen included names, email addresses, telephone numbers, dates of birth, hashed passwords (using MD5), and encrypted or unencrypted security questions and answers.
The 2013 breach was never officially attributed. The attack vector was not definitively identified. Forensic analysis was hampered by the three-year gap between the breach and its detection, and by Yahoo's limited security logging at the time of the incident. Yahoo's security team was aware of parts of the 2014 breach by late 2014 but did not connect it to the broader 2013 incident until later analysis. The question of why it took until 2016 to disclose breaches from 2013 and 2014 was the subject of SEC investigation.
In April 2018, Yahoo's successor company Oath (subsequently renamed Verizon Media, then Yahoo once more) settled SEC charges for $35 million. The SEC alleged that Yahoo had failed to disclose a material cybersecurity incident as required by securities laws. This was the first SEC enforcement action against a public company for breach disclosure failures, and it established breach disclosure as a securities law obligation - not just a privacy or breach notification law obligation.
The Criminal Case
The indictment of FSB officers alongside criminal hackers was unusual - it explicitly alleged a working relationship between Russian intelligence and career cybercriminals. The FSB officers directed the operation's intelligence collection components; the criminal hackers provided technical capabilities and took advantage of the access for their own financial gain (Baratov was paid per-account for accessing specific targets; Belan used the access to harvest financial account credentials).
Karim Baratov, the Canadian-Kazakh hacker, was arrested in Canada and extradited to the United States. He pled guilty to all charges and was sentenced to five years in federal prison. He was the only one of the four defendants to face US justice - the FSB officers and Belan remained in Russia, and extradition requests were not expected to be honored.
The case was notable for explicitly connecting Russian state intelligence activity to criminal profit-taking. The FSB officers allegedly knew Belan was using his access for personal financial gain and allowed it - treating his criminal side activities as a tolerated benefit of his cooperation, not a violation of their arrangement. This mirrors the broader pattern of Russian state tolerance for criminal hackers who maintain usefulness to intelligence services.