2014 Yahoo! data breach

Last reviewed:

The 2014 Yahoo! data breach was a significant cybersecurity incident in which attackers compromised the personal data of approximately 500 million Yahoo! user accounts. The breach, which was publicly disclosed in 2016, is considered one of the largest data breaches in history. The compromised data included names, email addresses, telephone numbers, dates of birth, hashed passwords, and, in some cases, encrypted or unencrypted security questions and answers. The breach had far-reaching implications for Yahoo!, its users, and the broader cybersecurity landscape.

Overview

In 2014, Yahoo! experienced a data breach that affected approximately 500 million user accounts. The breach was not publicly disclosed until 2016, when Yahoo! announced that a "state-sponsored actor" was responsible. The compromised data included personal information such as names, email addresses, telephone numbers, dates of birth, and hashed passwords. The breach had significant consequences for Yahoo!, including financial losses, legal challenges, and reputational damage.

Background

Yahoo!, founded in 1994, was one of the early pioneers of the internet, providing a wide range of services including email, news, and search. By 2014, Yahoo! was a major player in the technology industry, with millions of users worldwide. However, the company faced increasing competition from other tech giants and was undergoing significant changes, including leadership transitions and strategic shifts.

Timeline

  • 2014: The data breach occurred, compromising approximately 500 million Yahoo! user accounts. The breach went undetected for two years.
  • September 2016: Yahoo! publicly disclosed the breach, attributing it to a state-sponsored actor. The announcement came during Yahoo!'s negotiations with Verizon Communications for a potential acquisition.
  • December 2016: Yahoo! disclosed another breach, which occurred in 2013, affecting over 1 billion accounts.
  • March 2017: The United States Department of Justice charged four individuals, including two Russian intelligence officers, in connection with the 2014 breach.
  • June 2017: Yahoo! completed its acquisition by Verizon Communications, resulting in the creation of a new entity called Oath Inc.

Impact

The 2014 Yahoo! data breach had significant consequences for the company and its users. The compromised data included sensitive personal information, which could be used for identity theft and other malicious activities. The breach also had financial implications for Yahoo!, as it resulted in a $350 million reduction in the company's sale price to Verizon Communications. Additionally, Yahoo! faced numerous legal challenges, including class-action lawsuits from affected users.

Attribution

Yahoo! attributed the 2014 data breach to a state-sponsored actor, although the specific nation-state was not publicly named. In March 2017, the United States Department of Justice charged four individuals, including two Russian intelligence officers, in connection with the breach. The charges alleged that the individuals engaged in a conspiracy to access Yahoo!'s network and steal user data.

Aftermath

Following the disclosure of the 2014 data breach, Yahoo! took several steps to enhance its cybersecurity measures. The company encouraged users to change their passwords and security questions and implemented additional security features, such as two-factor authentication. Yahoo! also faced regulatory scrutiny and legal challenges, resulting in settlements and fines. The breach highlighted the importance of robust cybersecurity practices and the potential consequences of data breaches for organizations and individuals.

Timeline of the 2014 Yahoo! Data Breach

See also

Sources

Categories: Incidents
Last updated: September 3, 2026