Become a MacRumors Supporter for $25/year with no ads, private forums, and more!

MacRumors

macrumors bot
Original poster
Apr 12, 2001
54,621
16,766



Yahoo has issued a new warning to account holders about malicious hacks linked to a third data breach that the company disclosed late last year.

The warning relates to more recent malicious activity targeting accounts between 2015 and 2016, most likely perpetrated by a "state actor", according to Yahoo. Specifically, the hacks are said to have been achieved by using "forged" cookies - the text-based keys that give web users access to username and password information without having to re-enter it - created by software stolen from within Yahoo's internal systems.

A message was sent to affected Yahoo users on Wednesday, warning them of the unauthorized access to their account, but Yahoo did not reveal how many people were notified.

yahoo-again-800x579.jpg

Hopefully the cookie was forged by a state known for such delicacies. #yahoo #security #baking pic.twitter.com/7gCeEd3Y51 - Joshua B. Plotkin (@jplotkin) February 15, 2017
Yahoo's announcement came just hours after reports that Verizon was close to a renegotiated deal to buy Yahoo's core assets at a lower price. Last year, Verizon agreed to buy Yahoo's core business for $4.83 billion, but on Wednesday Bloomberg reported that the renegotiated deal would slash about $250 million off that price because of the security breaches that were revealed after the initial deal was agreed. 
"As we have previously disclosed, our outside forensic experts have been investigating the creation of forged cookies that could have enabled an intruder to access our users' accounts without a password," a Yahoo spokesperson told Associated Press. "The investigation has identified user accounts for which we believe forged cookies were taken or used. Yahoo is in the process of notifying all potentially affected account holders. Yahoo has invalidated the forged cookies so they cannot be used again."
Back in September, Yahoo revealed that hackers had stolen the personal data of "at least" 500 million users, but by December, the internet company admitted that over one billion Yahoo user accounts had been compromised in a separate hack dating back to August 2013. Information stolen included names, email addresses, phone numbers, birth dates, hashed passwords, security questions and answers.

The internet company is currently under investigation from the Securities and Exchange Commission over its failure to disclose its massive data breaches sooner.

Article Link: Yahoo Warns Users of Third Data Breach As Verizon Closes in on Revised Deal
 

sudo1996

Suspended
Aug 21, 2015
1,496
1,182
Berkeley, CA, USA
Forged cookies?! Geez, that's about as bad as it gets.
[doublepost=1487242386][/doublepost]
We don't need Yahoo anymore. They just need to die along with Adobe Flash.
One exception: Yahoo! Finance is still useful because Google Finance kinda sucks. And speaking of Flash, Google uses it for interactive charts for some reason.
[doublepost=1487242437][/doublepost]
Seriously? Forged cookies? What is this, 1998?
No. This. Is. Yahoo!!!!
 
Last edited:

MadeTheSwitch

macrumors 65816
Apr 20, 2009
1,074
15,660
A 250 million dollar discount still isn't enough. It's been clear for a long time that yahoo has been a lax company floundering around rudderless with no direction which have allowed these problems to happen. Whoever buys this company is inheriting a mess. Not really sure why Verizon even wants them.
 
  • Like
Reactions: TonyC28 and maflynn

willmtaylor

macrumors G4
Oct 31, 2009
10,309
8,190
Here(-ish)
Turns out, the "state actor" was just a stand-in for Romeo in a local theater production trying to figure out how to disable ads in his inbox.
 

MacBH928

macrumors 604
May 17, 2008
6,598
2,743
I just hate people like Marissa Mayer who seem so excited to change the world and once they fail they hide away... she is hardly tweeting. False promises.

That being said, what is it that Verizon willing to pay Yahoo $4.8B for? Also, Market Cap of Yahoo is $43B , is it just made of the Ali Baba shares?
 
  • Like
Reactions: tonyr6

Porco

macrumors 68040
Mar 28, 2005
3,200
6,383
A great philosopher once sang:

"If moon was cookie me think me would be
Happiest monster you ever see

Me put on a space suit then up through the night
Me ride in a rocket to go take a bite

Me take bite from here
Me take bite from there
And pretty soon, me bite everywhere

Me eat with both hands
No need fork or spoon
Me chew it all up until there no moon

If moon was cookie it wouldn't be fine
Because if me ate it then it wouldn't shine

Me come to the window and look up at night
But no little moonbeams would give me their light

So me not like to say it, but it clear to me
It lucky the moon is not a cookie."
 

maflynn

Moderator
Staff member
May 3, 2009
68,619
36,349
Boston
Why even password protect my yahoo account anymore? It seems like everyone else can access my stuff except me.
I cancelled and deleted my yahoo account.

I never really used them for emails so I'm happy about that, but the last hacking (prior to this) caused to me act. I recommend moving off of them
 
  • Like
Reactions: kazmac

Jnesbitt82

macrumors 6502
Oct 21, 2013
322
240
Ohio
I cancelled and deleted my yahoo account.

I never really used them for emails so I'm happy about that, but the last hacking (prior to this) caused to me act. I recommend moving off of them

For what it's worth, my AOL email from 1999 is still going strong. :)

I think yahoo needs to go away after this latest breach.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.