Yahoo suffered two of the largest data breaches in history - and disclosed them years after they occurred, during the process of being acquired by Verizon. The first breach, from 2014, compromised 500 million accounts. The second, from 2013, compromised 3 billion accounts - every Yahoo account that existed at the time. The delayed disclosure, the scale, and the acquisition context made the Yahoo breaches a defining moment in corporate breach disclosure practices and the legal obligations of companies undergoing M&A transactions.
The 2014 Breach
In late 2014, attackers compromised Yahoo's user database and exfiltrated records for approximately 500 million accounts. The data included names, email addresses, telephone numbers, dates of birth, hashed passwords (using bcrypt, a relatively strong hashing algorithm), and in some cases encrypted or unencrypted security questions and backup email addresses.
Yahoo did not discover the breach in 2014. They discovered it in 2016 when a data broker offered a dataset purportedly containing Yahoo user data for sale on a dark web forum. Yahoo investigated and confirmed the breach's existence in September 2016 - two years after the initial compromise. The company attributed the attack to "a state-sponsored actor" - subsequently identified as officers of Russia's FSB (Federal Security Service) and their criminal associates.
The 2013 Breach
In December 2016, Yahoo disclosed a second breach - separate from the 2014 incident - that had occurred in August 2013. This breach compromised approximately 1 billion accounts, as Yahoo initially estimated. In October 2017, following Verizon's acquisition of Yahoo's internet business, Oath (the Verizon subsidiary formed from the acquisition) revised the estimate to 3 billion accounts - the entire Yahoo user base at the time.
The 2013 breach used a different mechanism: MD5-hashed passwords rather than bcrypt. MD5 is a cryptographically broken hash function that is easily reversed with rainbow tables and GPU cracking. The security questions and answers in this breach were unencrypted. The full scope of data compromised included names, email addresses, telephone numbers, dates of birth, hashed passwords, and security questions/answers in cleartext or easily reversible form.
The Verizon Acquisition Context
Yahoo had announced in July 2016 that Verizon would acquire Yahoo's internet business for $4.8 billion. The 2014 breach was disclosed in September 2016, during the pending acquisition. The 2013 breach was disclosed in December 2016, still during the acquisition process.
Verizon renegotiated the deal downward by $350 million following the breach disclosures, completing the acquisition for approximately $4.48 billion. The breaches raised questions about material disclosure obligations in M&A transactions: Yahoo's leadership had known about the 2014 breach investigation for months before disclosing it to Verizon or the public. The SEC subsequently investigated Yahoo's disclosure timing.
In 2018, Yahoo's successor entity (Altaba, the company that remained after Verizon acquired Yahoo's operating business) agreed to an $85 million settlement with users affected by the breaches. The same year, the SEC charged Altaba with failing to disclose the 2014 breach to investors in a timely manner, reaching a $35 million settlement - the first time the SEC had charged a company for failing to disclose a cybersecurity incident to investors.
Russian Attribution and Indictments
In March 2017, the US Department of Justice unsealed an indictment charging four individuals with the 2014 Yahoo breach: two officers of Russia's FSB (Dmitry Dokuchaev and Igor Sushchin), and two criminal hackers they had recruited (Alexsey Belan and Karim Baratov). This was the first time US prosecutors had indicted Russian state intelligence officers for cybercrime.
Dokuchaev and Sushchin were arrested in Russia - not for the Yahoo hack, but by Russia's own FSB, for treason. They were accused of providing information to the CIA. Their arrests inside Russia, shortly after the US indictment, led to speculation about whether the US had provided information to Russia that contributed to their identification. Neither was extradited.
Belan, a Latvian national and wanted cybercriminal, was never apprehended in connection with the Yahoo breach - he remains on the FBI's most wanted list. Baratov, a Canadian national, was arrested in Canada and extradited to the United States. He pleaded guilty and was sentenced to five years in federal prison.
The Password Reuse Cascade
The full harm from the Yahoo breaches extended far beyond Yahoo itself. The combination of email addresses and passwords (even hashed) enabled credential stuffing attacks against any service where Yahoo users had reused their passwords. The 2013 breach's MD5 hashes were trivially crackable - rainbow tables for common passwords meant a significant fraction of accounts yielded plaintext passwords quickly.
Given that Yahoo was a major email provider, the breaches also compromised account recovery for other services. Many users had configured password resets for other accounts to send to their Yahoo email address. Control of a Yahoo email account translated directly to account takeover capability for any other service that offered email-based password recovery.
The Yahoo breaches were the largest-scale demonstration of why password reuse and recoverable account credentials create cascade risk across the internet. Three billion compromised accounts - half the internet's users at the time - represented a credential database for attackers that is still being used years later. Credential stuffing attacks in 2020, 2021, 2022 continued to use Yahoo data from the 2013 breach, as users who had never changed passwords from their Yahoo accounts continued to reuse those credentials elsewhere.