Yahoo suffered two separate data breaches - the largest in history at the time of their disclosure - that together resulted in the theft of data from all 3 billion Yahoo user accounts. The first breach occurred in 2013; the second in 2014. Yahoo disclosed the 2014 breach in September 2016, nearly two years after it occurred. Yahoo disclosed the 2013 breach in December 2016, more than three years after it occurred. The delayed disclosures, combined with the unprecedented scale, made the Yahoo breaches a landmark case for both cybersecurity incident response and the governance failures that allowed breaches of this magnitude to go undetected and undisclosed for years.

The timing of the disclosures was not coincidental. Yahoo was in the process of selling itself to Verizon for $4.83 billion when the breaches were revealed. The disclosures triggered renegotiation of the deal, which ultimately closed at $4.48 billion - a $350 million reduction attributed to the breach liability. It was the first major case where a cybersecurity breach materially impacted an M&A transaction, and it made breach disclosure a mandatory due diligence item in every technology M&A deal that followed.

The 2014 Breach: State-Sponsored Hackers

The 2014 breach was attributed by the FBI and DOJ to four individuals: two officers of the Russian FSB (Federal Security Service) and two criminal hackers working with them. In March 2017, the DOJ indicted Dmitry Dokuchaev and Igor Sushchin (FSB officers), Alexsey Belan (a career criminal hacker on the FBI's Cyber Most Wanted list), and Karim Baratov (a Canadian-Kazakh freelance hacker). The indictment alleged that the FSB officers directed Belan and Baratov to use stolen Yahoo account credentials to access accounts of interest to Russian intelligence - including those of Russian journalists, US government officials, Russian opposition figures, and a Swiss bitcoin wallet service.

The 2014 breach used spear-phishing to obtain access to Yahoo's corporate network, where the attackers compromised the Yahoo Account Management Tool - an internal system that allowed Yahoo employees to access and manage user accounts. With this tool, they were able to create forged authentication cookies (called "nonces") that allowed them to access any Yahoo account without knowing the password. They also stole Yahoo's user database, which contained username, email address, phone number, date of birth, hashed passwords (using MD5 - a cryptographically broken hash function), and security questions and answers (encrypted with bcrypt in some accounts, stored in plaintext in others).

The use of MD5 for password hashing was a significant aggravating factor. MD5 produces hashes that can be cracked with GPU-accelerated dictionary attacks in seconds to minutes for common passwords. The stolen Yahoo password database was effectively a partially cracked credential database for anyone who obtained it. Given that password reuse across services was (and remains) common, many of the stolen Yahoo credentials would have been valid for other accounts.

[TECHNICAL NOTE]
Yahoo's account security architecture at the time of the 2014 breach reflected the state of industry practice circa 2010-2012: MD5 password hashing (broken by 2004 for collision attacks, and by 2010 largely considered too fast for password hashing), security questions stored with reversible encryption, and an internal administrative tool that provided privileged access to user accounts without logging comprehensive audit trails. The Account Management Tool access - which allowed cookie forging - was the most operationally damaging capability stolen. An attacker who could forge authentication cookies didn't need to crack passwords; they could silently access any target account by generating a valid-appearing cookie for that account. Cookie forging attacks were the primary mechanism used to access accounts of intelligence interest; password database theft was the broader data collection for resale or future exploitation. Post-breach, Yahoo moved to bcrypt for all new passwords (the correct approach - bcrypt's computational cost makes brute-force cracking impractical), eliminated persistent long-lived authentication cookies, and deployed hardware security keys for employee accounts. The breach also accelerated Yahoo's adoption of account key notifications that alerted users when their accounts were accessed from new devices.

The 2013 Breach: All 3 Billion Accounts

The 2013 breach was initially disclosed in December 2016 as affecting "more than 1 billion" accounts. In October 2017, after Verizon had completed the Yahoo acquisition (rebranded as Oath), new forensic analysis revealed that the 2013 breach had actually affected all 3 billion Yahoo accounts that existed at the time - the largest data breach in history by account count. The data stolen included names, email addresses, telephone numbers, dates of birth, hashed passwords (using MD5), and encrypted or unencrypted security questions and answers.

The 2013 breach was never officially attributed. The attack vector was not definitively identified. Forensic analysis was hampered by the three-year gap between the breach and its detection, and by Yahoo's limited security logging at the time of the incident. Yahoo's security team was aware of parts of the 2014 breach by late 2014 but did not connect it to the broader 2013 incident until later analysis. The question of why it took until 2016 to disclose breaches from 2013 and 2014 was the subject of SEC investigation.

In April 2018, Yahoo's successor company Oath (subsequently renamed Verizon Media, then Yahoo once more) settled SEC charges for $35 million. The SEC alleged that Yahoo had failed to disclose a material cybersecurity incident as required by securities laws. This was the first SEC enforcement action against a public company for breach disclosure failures, and it established breach disclosure as a securities law obligation - not just a privacy or breach notification law obligation.

[WARNING]
The Yahoo case established several precedents that shaped corporate cybersecurity governance. First, breach disclosure timing: the SEC enforcement action created direct liability for failing to disclose breaches on a timely basis. Combined with state breach notification laws and the EU GDPR's 72-hour breach reporting requirement (adopted 2016, effective 2018), Yahoo accelerated the trend toward mandatory breach disclosure windows. Second, M&A due diligence: the $350M Verizon deal price reduction demonstrated that undisclosed breaches are material information in acquisition due diligence. Every technology M&A deal since has included cybersecurity due diligence as a standard component. Third, security leadership accountability: Yahoo's CISO, Alex Stamos, publicly distanced himself from the Yahoo breach response and ultimately departed for Facebook. The question of CISO authority, resources, and accountability in preventing and disclosing breaches became a boardroom governance issue. Fourth, password storage practices: Yahoo's use of MD5 for password hashing became the canonical "do not do this" example in every security architecture discussion.

The Criminal Case

The indictment of FSB officers alongside criminal hackers was unusual - it explicitly alleged a working relationship between Russian intelligence and career cybercriminals. The FSB officers directed the operation's intelligence collection components; the criminal hackers provided technical capabilities and took advantage of the access for their own financial gain (Baratov was paid per-account for accessing specific targets; Belan used the access to harvest financial account credentials).

Karim Baratov, the Canadian-Kazakh hacker, was arrested in Canada and extradited to the United States. He pled guilty to all charges and was sentenced to five years in federal prison. He was the only one of the four defendants to face US justice - the FSB officers and Belan remained in Russia, and extradition requests were not expected to be honored.

The case was notable for explicitly connecting Russian state intelligence activity to criminal profit-taking. The FSB officers allegedly knew Belan was using his access for personal financial gain and allowed it - treating his criminal side activities as a tolerated benefit of his cooperation, not a violation of their arrangement. This mirrors the broader pattern of Russian state tolerance for criminal hackers who maintain usefulness to intelligence services.

[IOC]
Yahoo breach technical indicators (historical): MD5-hashed passwords from the 2013/2014 breaches circulated in underground markets for years post-disclosure; any MD5 hash from Yahoo's database can be checked against rainbow tables and cracked for common passwords. The 2014 breach's cookie forgery mechanism used knowledge of Yahoo's internal cookie signing key; if Yahoo accounts appeared to be accessed from unusual IP addresses without a password login event in the same session, this was a potential indicator of cookie forgery. Yahoo users should assume their pre-2016 passwords are compromised and have been in circulation; password reuse on any other service with those credentials is a persistent risk. The indicted individuals: Dmitry Dokuchaev (FSB officer; also arrested in Russia in 2017 on treason charges, believed to have been working with US intelligence), Igor Sushchin (FSB officer), Alexsey Belan (DOB 1987, Latvian-Russian, FBI Cyber Most Wanted; believed in Russia), Karim Baratov (aka Kay, Soltan, Karim Taloverov; sentenced 5 years, released 2022). DOJ case: Northern District of California, United States v. Dokuchaev et al.