Usernames and passwords of some of Yahoo’s e-mail customers have been stolen and used to gather personal information about people those Yahoo mail users have recently corresponded with, the company said on Thursday.
Yahoo did not say how many accounts have been affected. Yahoo is the second-largest e-mail service worldwide, after Google’s Gmail, according to the research firm comScore. There are 273 million Yahoo mail accounts worldwide, including 81 million in the US.
It is the latest in a string of security breaches that have allowed hackers to nab personal information using software that analysts say is ever more sophisticated. Up to 70 million customers of Target stores had their personal information and credit and debit card numbers compromised late last year, and Neiman Marcus was the victim of a similar breach last month.
“It’s an old trend, but it’s much more exaggerated now because the programs the bad guys use are much more sophisticated now,” says Avivah Litan, a security analyst at the technology research firm Gartner. “We’re clearly under attack.”
Yahoo Inc said in a blog post on its breach that “The information sought in the attack seems to be names and e-mail addresses from the affected accounts’ most recent sent e-mails.”
That could mean hackers were looking for additional e-mail addresses to send spam or scam messages. By grabbing real names from those sent folders, hackers could try to make bogus messages appear more legitimate to recipients.
“It’s much more likely that I’d click on something from you if we e-mail all the time,” says Richard Mogull, analyst and CEO of Securois, a security research and advisory firm.
The bigger danger: access to e-mail accounts could lead to more serious breaches involving banking and shopping sites. That’s because many people reuse passwords across many sites, and also because many sites use e-mail to reset passwords. Hackers could try logging in to such a site with the Yahoo e-mail address, for instance, and ask that a password reminder be sent by e-mail.
Litan said hackers appear to be “trying to collect as much information as they can on people. Putting all this stuff together makes it easier to steal somebody’s identity.”
Yahoo said the usernames and passwords were not collected from its own systems, but from a third-party database.
Because so many people use the same passwords across multiple sites, it is possible hackers broke in to some service that lets people use e-mail addresses as their usernames. The hackers could have grabbed passwords stored at that service, filtered out the accounts with Yahoo addresses and used that information to log in to Yahoo’s mail systems, said Johannes Ullrich, dean of research at the SANS Institute, a group devoted to security research and education.
The breach is the second mishap for Yahoo’s mail service in two months. Last month, the service suffered a multi-day outage that prompted Yahoo CEO Marissa Mayer to issue an apology.
Yahoo said it is resetting passwords on affected accounts and has “implemented additional measures” to block further attacks. The company would not comment beyond the information in its blog post. It said it is working with federal law enforcement.
Stephen Garrett, a 27-year-old graduate student, always thought he would study in China, but first the country’s restrictive COVID-19 policies made it nearly impossible and now he has other concerns. The cost is one deterrent, but Garrett is more worried about restrictions on academic freedom and the personal risk of being stranded in China. He is not alone. Only about 700 American students are studying at Chinese universities, down from a peak of nearly 25,000 a decade ago, while there are nearly 300,000 Chinese students at US schools. Some young Americans are discouraged from investing their time in China by what they see
MAJOR DROP: CEO Tim Cook, who is visiting Hanoi, pledged the firm was committed to Vietnam after its smartphone shipments declined 9.6% annually in the first quarter Apple Inc yesterday said it would increase spending on suppliers in Vietnam, a key production hub, as CEO Tim Cook arrived in the country for a two-day visit. The iPhone maker announced the news in a statement on its Web site, but gave no details of how much it would spend or where the money would go. Cook is expected to meet programmers, content creators and students during his visit, online newspaper VnExpress reported. The visit comes as US President Joe Biden’s administration seeks to ramp up Vietnam’s role in the global tech supply chain to reduce the US’ dependence on China. Images on
New apartments in Taiwan’s major cities are getting smaller, while old apartments are increasingly occupied by older people, many of whom live alone, government data showed. The phenomenon has to do with sharpening unaffordable property prices and an aging population, property brokers said. Apartments with one bedroom that are two years old or older have gained a noticeable presence in the nation’s six special municipalities as well as Hsinchu county and city in the past five years, Evertrust Rehouse Co (永慶房產集團) found, citing data from the government’s real-price transaction platform. In Taipei, apartments with one bedroom accounted for 19 percent of deals last
US CONSCULTANT: The US Department of Commerce’s Ursula Burns is a rarely seen US government consultant to be put forward to sit on the board, nominated as an independent director Taiwan Semiconductor Manufacturing Co (TSMC, 台積電), the world’s largest contract chipmaker, yesterday nominated 10 candidates for its new board of directors, including Ursula Burns from the US Department of Commerce. It is rare that TSMC has nominated a US government consultant to sit on its board. Burns was nominated as one of seven independent directors. She is vice chair of the department’s Advisory Council on Supply Chain Competitiveness. Burns is to stand for election at TSMC’s annual shareholders’ meeting on June 4 along with the rest of the candidates. TSMC chairman Mark Liu (劉德音) was not on the list after in December last