Technology by Design

Technology news, reviews, and how to keep your technology running fast and smooth!

  • Home
  • About TbyD
    • Who is TbyD
    • Why Choose TbyD?
    • 16 Things
    • Your Computer Guy
  • Products and Services
    • Business Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
      • Performance Analysis
      • Optimization
      • Core Security Solution
      • Managed Backups
      • Computer and Network Systems
      • Computer Setup
      • Domain Names
      • Email Services
      • Extended Warranties
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
      • Websites
    • Services
      • Monthly Service Plans
        • Enterprise Service Plan
        • Business Service Plan
        • Personal Service Plan
        • Computer Setup
      • Core Security Solution
      • Managed Backups
      • Extended Warranties
      • Performance Analysis
      • Optimization
      • Network Cabling Services
      • Security Camera Systems
      • Managed Spam Filters
      • VoIp Phone Systems
    • Products
      • Computers
      • Servers
  • Testimonials
    • What Our Clients Say About Us
  • Blogs
    • ALERTS
    • FAQ
    • How To Videos
  • Newsletters
    • TechTips Newsletters
  • Reviews
  • Media
    • Email Red Flags
    • E-Books
    • Disaster Prevention Planning Kit
    • Free Reports
  • Contact Us
    • Contact Us
    • Quick Support

Yahoo Hack Extends Further Than Just Passwords

September 26, 2016 by The T By D Team Leave a Comment

yahoo-hackYahoo Hack Extends Further Than Just Passwords

Yahoo recently went public regarding “information associated with at least 500 million user accounts was stolen from its network in 2014 by what it believed was a “state-sponsored actor.”  The data stolen may have included names, email addresses, telephone numbers, dates of birth, and hashed passwords (the vast majority with the relatively strong bcrypt algorithm) but may not have included unprotected passwords, payment card data or bank account information, the company reported at the time.  Later on, Yahoo disclosed that more credentials were stolen and that more data (credit cards) was exfiltrated than was known at the time of the discovery.  

Yahoo is working with law enforcement on the matter, and has launched an investigation into a possible breach in early August after a Russian hacker named “Peace” offered to sell a data dump of over 200 million Yahoo accounts on the darknet for a mere $1,800 which included usernames, easy-to-crack password hashes, dates of birth, and backup email addresses.  

Why Should You Worry?

Well, if you change your password regularly (every month or so), and use difficult to guess passwords (ie. NOT “123456” or “password”, or even the ever-popular “abc123”), then you should be good initially (unless, of course, they have your credit card info, in which case you should cancel your cards immediately).  However, the hackers aren’t quite done with you…

  1. Phishing attacks will likely be the number one strategy, with Yahoo user accounts being used for social engineering attacks.  These are usually highly successful, and lucrative, for hackers.
  2. However, since many people use the same username & passwords across multiple sites, the other attack you have to watch for is “credential-stuffing”.  This is a brute-force attack where attackers inject stolen usernames and passwords into a website until they find a match using the stolen Yahoo username and passwords.
  3. Yahoo has put a security announcement on their website, and has started to send users notices that they need to change their password.  CyberCriminals were grateful, I’m sure, as they are going to spoof this and rake in the money.  The emails being sent out look similar to below:

Subject:  Your Yahoo account

The security of your Yahoo account, [Name], is important to us.  Out of an abundance of caution, we are asking you to change your password.  We are committed to protecting the security of our user’s information, and we take measures like this when appropriate in light of reported security issues or suspicious activity on an account.

We encourage you to take the following steps:

  1.  Sign into your account and change your password:

https://login.yahoo.com/account/change-password

2.  Visit our Help Page for information on safeguarding your account:

https://help.yahoo.com/kb/account/safeguard-yahoo-account-sln2080..html

Or

Start using Yahoo Account Key and never get locked out from forgetting or losing your password.  Yahoo Account Key is a convenient way to control access to your account, and it’s more secure than a traditional password because once you activate Account Key – even if someone gets access to your account info – they can’t sign in.

https://login.yahoo.com/account/security/mc-yak-optin

Yahoo

How To Protect Yourself:
  1. Do NOT click on any links contained within an email, even if the email looks legit.  Type in the address yourself into your browser bar.
  2. Do NOT phone any phone numbers contained within an email.  Look up the phone number yourself, directly on the company website.  
  3. Do NOT use the same usernames and passwords on multiple accounts.  Using the same password on multiple accounts is an invitation to get hacked.  If you did use your Yahoo passwords on other sites, go to those sites, and change those passwords there too.  Also change the security questions and make the answers non-obvious.
  4. Use a free password manager that can generate hard-t0-hack passwords, keep, and remember them for you.
  5. Watch out for phishing emails that relate to Yahoo in any way, especially if they ask you to click on links, or if they are asking for information.
  6. Now would be a good time to sign up for Yahoo Account Key – a simple authentication tool that eliminates the need to use a password altogether.  
You can’t stop CyberCriminals from targeting your company or employees.
But you can be prepared for their arrival, and have full shields up.

Got CyberBugs?

Call 1-204-800-3166

For Cyber-Extermination!

#itthatworks

Filed Under: ALERTS, Blogs

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Sign Up For The Monthly TechTips Newsletter!

* = required field
unsubscribe from list

powered by MailChimp!

Recent Posts

  • ALERT: Celebrity Death Scams
  • ALERT: Uber Hacked
  • ALERT: Netflix Email Scam
  • ALERT: Bad Rabbit
  • Scam – Reset Password Alert

Recent Comments

  • ALERT: New Ransomware Targets MS Office 365 Users - Technology by Design on Managed Backups
  • ALERT: FBI Warns Email Extortion Heating Up for Summer! - Technology by Design on ALERT: AshleyMadison Hack Blows Up
  • ALERT: Evil Android Trojan Empties Your Bank Account - Technology by Design on Definition: Phishing
  • ALERT: HTML Attachments - Technology by Design on Definition: Phishing
  • ALERT: New Ransomware Also Steals Your Bitcoins - Technology by Design on Managed Backups

Copyright © 2025 · Dynamik Website Builder on Genesis Framework · WordPress · Log in