>

Scam Of The Week: The 1 Billion Yahoo Hack

  • Alien
  • Topic Author
  • Visitor
  • Visitor
23 Dec 2016 16:15 #329962 by Alien
Scam Of The Week: The 1 Billion Yahoo Hack
Stu Sjouwerman
This is getting old. It's all over the press... again.  Here is a Reuters article where I am quoted, which covers the most recent billion-record Yahoo hack.

Some people asked me after our Flash announcement last week: "Stu, really, these hacks happened a few years ago, closing down my whole Yahoo account, or blocking Yahoo at the firewall... aren't you going a bit overboard here?"

Good question. Here is my take:
Well, that whole 1B database was sold on the dark web by a group of professional blackhats from Eastern Europe for 300K, (and is still for sale at a much lower price right now) which means that a ton of bad guys now have these credentials, but worse, they have answers to security questions like "your mother's maiden name" which do not change like passwords, and and backup email addresses that could help with resetting forgotten passwords.

Bloomberg reported that 150,000 U.S. government and military employees are among the victims in the latest breach.

My position is that all Yahoo accounts need to be considered compromised. They are sitting ducks for spam, phishing and malware attacks. If employees check their Yahoo account on their lunch break, do you want to expose your company network to that?

It looks like Yahoo has not learned their lessons, so new hacks can happen any time. There has been an exodus of qualified Yahoo staff and they seem to be unable to apply best security practices. They are now forcing all users (link to WSJ article) to change their password, but that's too little, too late. I simply have lost trust.

So, I recommend you warn your users, friends and family... again. We have been here before on September 23rd when the 500 million record hack was first announced.

In September, Yahoo did not force people to change passwords, but now they are forcing a password change, and the bad guys are (again) all over this -- the ones that own the Yahoo database but also the ones that do not, because news like this is a phishing paradise.

This is a phishing paradise with significant fallout

Phishing attacks likely will be the number one possible fallout, with Yahoo user accounts being used for social engineering attacks. However, since many people use the same username and passwords across multiple sites, the other thing that will continue to happen is called "credential-stuffing", a brute-force attack where attackers inject stolen usernames, passwords and possibly the answers to security questions into a website until they find a match using the stolen Yahoo username and passwords. 

The bad guys will continue to exploit this, so remind your users

Remind your users, friends and family. They will be likely be confronted with Yahoo-related scams in their inbox. The bad guys are going to leverage this in a variety of ways, starting with bogus password reset phishing attacks, but also with masked links so that if you click on it you wind up on a compromised site which could steal personal information and/or infect the computer. The variations are infinite, but the defense against it is relatively simple.

I suggest you send them the following reminder - feel free to copy/paste/edit:

"Yahoo announced that 1 billion of their accounts were hacked. These accounts are now sold by internet criminals to other bad guys which are going to use this information in a variety of ways. For instance, they will send phishing emails claiming you need to change your Yahoo account, looking just like the real ones.  Here is what I suggest you do right away.
If you do not use your Yahoo account a lot. Close it down because it's a risk. If you use it every day:
Open your browser and go to Yahoo. Do not use a link in any email. Reset your password and make it a strong, complex password or rather a pass-phrase.

If you were using that same password on multiple websites, you need to stop that right now. Using the same password all over the place is an invitation to get hacked. If you did use your Yahoo passwords on other sites, go to those sites and change the password there too. Also change the security questions and make the answer something non-obvious.
At the house, use a free password manager that can generate hard-to-hack passwords, keep and remember them for you.
Watch out for any phishing emails that relate to Yahoo in any way and ask for information.
Now would also be a good time to use Yahoo Account Key, a simple authentication tool that eliminates the need to use a password altogether.
Yahoo Breach Phishing TemplateIf you are a KnowBe4 customer, we have a template in the Current Events Campaign which I suggest you send to all your users immediately as a reminder.

This is the largest hack ever, below is a graph fresh from an article in the Wall Street Journal that puts it in perspective. I suggest you send this to your management.

This is exactly the kind of thing that they want to prevent from happening and security awareness training is the number one thing that makes your organization more hack-resistant since your users are your weakest IT security link.

Please Log in or Create an account to join the conversation.

  • Alien
  • Topic Author
  • Visitor
  • Visitor
23 Dec 2016 16:16 #329963 by Alien


I don't have a yahoo account , so I am cool. 8)

Please Log in or Create an account to join the conversation.

  • tpicks
  • Visitor
  • Visitor
23 Dec 2016 16:20 #329966 by tpicks
I do have account in Yahoo. I have long taken all the security measures advised by Yahoo to keep safe and secured again.

Please Log in or Create an account to join the conversation.

Time to create page: 0.191 seconds
JulieEngland cricket icon Robin Smith has passed away at the age of 62.(03.12.2025, 20:30)(20:30)0
JulieFormer Jets and Commanders WR Laveranues Coles completed nine months of training at the Jacksonville Sheriff's Office Academy and will officially become an officer after his probationary period ?(02.12.2025, 14:36)(14:36)0
JulieHeartbreaking to hear of the passing of former England cricketer Robin Smith ?

Our thoughts are with his friends and family at this difficult time ?

Rest in peace, Judge ?
(02.12.2025, 12:56)(12:56)0
JulieJUST IN: Andre Russell calls time on his IPL career and will join KKR’s support staff for 2026 ‼️(30.11.2025, 14:06)(14:06)0
TravisShoppers spend billions on Black Friday to snag holiday deals, despite wider economic uncertainty(29.11.2025, 17:11)(17:11)0
TravisSnow, rain and cold in store for some Thanksgiving travelers(29.11.2025, 17:10)(17:10)0
TravisThe pitch at Perth Stadium was rated "very good" despite a two-day finish in the first Ashes Test(29.11.2025, 10:57)(10:57)0
TravisWe are two days out or so from the start of the New Zealand vs West Indies test series.(29.11.2025, 10:51)(10:51)0
TravisPat Cummins did look brilliant in the nets over in Perth but will only be readier for his return come the 3rd Test in Adelaide, which should work perfectly for Australia, especially now that they’re 1-0 up going to the Gabba(29.11.2025, 10:41)(10:41)0
JulieSad news: Thirty minutes ago in Dallas, the family of former Dallas Cowboys icon Drew Pearson, aged 73, unexpectedly announced that he has passed away(29.11.2025, 08:00)(08:00)0
TravisPat Cummins is set to be included in Australia’s squad for the upcoming second Ashes Test against England in Brisbane, according to reports.(28.11.2025, 15:19)(15:19)0
TravisSuspect in shooting of National Guard members now facing a first-degree murder charge(28.11.2025, 14:24)(14:24)0
TravisLake effect snow piles up in Great Lakes region, impacting Thanksgiving travel(28.11.2025, 08:50)(08:50)0
TravisChiefs vs. Cowboys preview Week 13






Perhaps the most perplexing aspect of AT&T Stadium, otherwise known as “Jerry World,” is the glare from the sun that bursts through the windows and shines directly onto the field. Time and time again the glare has impacted players’ visibility during games, yet Jerry Jones refuses to make any changes to account for the sun.

Rather than install curtains, Jones has previously said he feels it’s a home-field advantage to have that type of stadium factor impacting games. Well, the glare ended up benefitting the Chiefs early into Thursday’s Thanksgiving game, as a pass from Dak Prescott to George Pickens fell incomplete, at least in part due to the impact of the sun’s glare.
(27.11.2025, 21:18)(21:18)0
TravisAT&T Stadium Glare Led to Plenty of Comments From NFL Fans During Chiefs-Cowboys(27.11.2025, 21:17)(21:17)0
TravisKittitian allrounder Kunal Tilokani earns U19 call upKittitian allrounder Kunal Tilokani earns U19 call up(27.11.2025, 13:19)(13:19)0
Travis'Wanted them to really grovel' - SA coach Shukri Conrad on keeping India on the field(25.11.2025, 18:29)(18:29)0
JulieHi(25.11.2025, 08:45)(08:45)0
Juliemotie 130 notout guyana 250(25.11.2025, 08:44)(08:44)0
Matthewhi(25.11.2025, 07:00)(07:00)0
Julie19 wickets fall between Aus and Eng and it’s great cricket, 19 wickets fall between W.I and any other country and we should be relegated…the double standards in world cricket.(21.11.2025, 06:40)(06:40)0
Travisketchim?(12.11.2025, 17:40)(17:40)0
Traviskwami?(12.11.2025, 17:40)(17:40)0
Traviswho is this(12.11.2025, 17:39)(17:39)0
AlvinChairmsn, I cant Log in(11.11.2025, 17:16)(17:16)0
SerenaThis batting performance by the West Indies in the second innings blew me away. I kept closing my eyes and then rubbing and opening them again and sat transfixed as I watch that unbelievable partnership between John Campbell and Shai Hope. What a magnificent performance by these two! It just goes to show that patience, determination and effort can go a long way to improve the performances of the West Indies team. Let us hope that this effort by West Indies batsmen would not be a one-off performance, but will be the beginning of a renewed effort to improve the performances of the team, going forward.(13.10.2025, 09:28)(09:28)0
SerenaJohn Campbell breaks a 23-year drought for West Indies openers with a Test hundred in India!

#INDvsWI #INDvWI #JohnCampbell
(13.10.2025, 05:49)(05:49)0
SerenaLet's celebrate that Ind will have to bat again as a notable achievement(13.10.2025, 05:32)(05:32)0
SerenaDefeat in Ahmedabad, we move to Delhi with an aim to the level the series.

#INDvWI | #MenInMaroon
(04.10.2025, 10:38)(10:38)0
Serena? USA Cricket Files for Bankruptcy

The Chapter 11 filing makes it the first known ICC member to declare bankruptcy. ⚡?
(03.10.2025, 12:22)(12:22)0
SerenaA maiden test wicket for Khary Pierre ends a challenging day 2️⃣

#INDvWI
(03.10.2025, 12:15)(12:15)0
SerenaWhy is WI best batter batting at #6 and why is he even keeping wickets in test?(03.10.2025, 07:26)(07:26)0
SerenaGive warrican vice captain on wat basis the man does nothing not even help chase(03.10.2025, 07:10)(07:10)0
SerenaWI waiting for declaration. India most likely will declare if or when both Jurel and Jadeja get to their 100s.(03.10.2025, 05:35)(05:35)0
Kade162 all out : India 121-2 stumps, day1(02.10.2025, 16:00)(16:00)0
Serenaif marriage certificate could get expire like driver's licence a lot of married men will never renew it(27.09.2025, 10:54)(10:54)0
WarrenJameis Winston is asked about being named QB3 on the Giants' roster behind Russell Wilson and Jaxson Dart:

"As a competitor, you want to be the starter. But I prepare to be the starter, I know I'm a starter in this league.

But you have to be able to be grateful for your role...my role right now is to assist Russ and Jaxson to be the best that they can be while preparing to be the best that I can be.

No matter if I'm 3, 33, this is my first year being number 19, so it's always a first for everything.

I focus on what I would love. And what I would love is for this team to have success."
(13.09.2025, 10:58)(10:58)0
Monicae(11.09.2025, 17:03)(17:03)0
RylandLol... Hetmyer. Fell agonizingly short of his century! Just 91 more he needed!(08.09.2025, 05:53)(05:53)0
RylandThe progress of the PPP government should not be judged by the dissenting voices of a few, but by the tangible benefits it has brought to everyone.(02.09.2025, 17:51)(17:51)0
Warren2 firefighters battling Washington state wildfire arrested by Border Patrol(29.08.2025, 10:51)(10:51)0
SalvadorPresident Ali hints at possible Christmas cash grant(27.08.2025, 12:36)(12:36)0
Sierrahi(27.08.2025, 12:07)(12:07)0
SergioWhat food could you eat every day of the week because you love it so much?(25.08.2025, 13:41)(13:41)0
KingsleyIsrael strikes a Gaza hospital twice, killing at least 20, including journalists and rescuers(25.08.2025, 11:27)(11:27)0
KingsleyShubman Gill returns to India's T20I squad as vice-captain for Asia Cup(20.08.2025, 12:54)(12:54)0
KingstonCanada's government forced Air Canada and its striking flight attendants back to work and into arbitration Saturday after a work stoppage stranded more than 100,000 travelers around the world.(16.08.2025, 18:08)(18:08)0
KingsleyGovernment papers found in an Alaskan hotel reveal new details of Trump-Putin summit(16.08.2025, 17:59)(17:59)0
LawrenceI'm confused how a cemetery can raise its funeral prices and blame it on the cost of living. ?(15.08.2025, 07:03)(07:03)0
LawrenceNext up West Indies play Nepal in a 3 match series (T20i), starting on the 27th Sept.(13.08.2025, 13:49)(13:49)0
Asa
Go to top