searchtwitterarrow rightmail strokearrow leftmail solidfacebooklinkedinplusangle upmagazine plus
Help Net Security - Daily information security news with a focus on enterprise security.
Help Net Security - Daily information security news with a focus on enterprise security.
  • News
  • Features
  • Expert analysis
  • Videos
  • Reviews
  • Events
  • Whitepapers
  • Industry news
  • Product showcase
  • Newsletters
Zeljka Zorz
Zeljka Zorz, Editor-in-Chief, Help Net Security
February 16, 2017
Share

Yahoo notifies more users of malicious account activity

Yahoo has sent out another round of account compromise notifications, warning users that hackers may have accessed their accounts by using forged cookies instead of passwords. How many in total, the company wouldn’t say.

Yahoo forged cookies

This attack is not exactly news, as the company disclosed it in November 2016 in a SEC filing. But, after the revelations about the massive Yahoo breaches from 2013 and 2014, it passed largely unnoticed.

A first round of notifications to potentially affected users went out in December 2016, but that was obviously not the end of it.

According to the SEC filing, the attacker – believed to be the same “state-sponsored actor” that had access to the Yahoo’s network in late 2014 – created cookies that allowed access to users’ accounts or account information without a password.

According to some of the notifications published by the most recent recipients, the attacker seems to have used the forged cookies to access user accounts in 2015 and 2016. Yahoo has invalidated those cookies in the meantime.

“While it is ‘news’ that Yahoo is making another announcement about a breach, it shouldn’t be surprising,” Jason Hart, Vice President and Chief Technology Officer at Gemalto.

“The company recommended that users consider adopting its Yahoo Account Key, an authentication tool that eliminates the need for a password. However, tools like this only work if the user remembers to activate them. Given the current security climate, all companies should have multi-factor authentication activated by default for all online accounts. Opt-in security is not an option in this day and age,” he noted. “Now, it only remains to see how much more of a discount Verizon may ask for.”

Yahoo is still in talks with Verizon about the planned acquisition, and the amount the internet giant will go for keeps falling.

More about
  • account hijacking
  • Yahoo
Share this

Featured news

  • Top ways attackers are targeting your endpoints
  • Why organizations shouldn’t fold to cybercriminal requests
  • Fake ChatGPT for Google extension hijacks Facebook accounts
How to protect online privacy in the age of pixel trackers

Sponsored

Webinar: Tips from MSSPs to MSSPs – starting a vCISO practice

Security in the cloud with more automation

CISOs struggle with stress and limited resources

How to scale cybersecurity for your business

Don't miss

Top ways attackers are targeting your endpoints

Why organizations shouldn’t fold to cybercriminal requests

Fake ChatGPT for Google extension hijacks Facebook accounts

A common user mistake can lead to compromised Okta login credentials

A closer look at TSA’s new cybersecurity requirements for aviation

Cybersecurity news
Help Net Security - Daily information security news with a focus on enterprise security.
© Copyright 1998-2023 by Help Net Security
Read our privacy policy | About us | Advertise
Follow us