Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 Posted - Sep 23 2016 : 4:20AM Yahoo Says Hackers Stole Data on 500 Million Users in 2014 SAN FRANCISCO - Yahoo announced on Thursday that the account information of at least 500 million users was stolen by hackers two years ago, in the biggest known intrusion of one company's computer network.
In a statement, Yahoo said user information - including names, email addresses, telephone numbers, birth dates, encrypted passwords and, in some cases, security questions - was compromised in 2014 by what it believed was a "state-sponsored actor."
While Yahoo did not name the country involved, how the company discovered the hack nearly two years after the fact offered a glimpse at the complicated and mysterious world of the underground web.
The hack of Yahoo, still one of the internet's busiest sites with one billion monthly users, also has far-reaching implications for both consumers and one of America's largest companies, Verizon Communications, which is in the process of acquiring Yahoo for $4.8 billion. Yahoo Mail is one of the oldest free email services, and many users have built their digital identities around it, from their bank accounts to photo albums and even medical information.
Changing Yahoo passwords will be just the start for many users. They'll also have to comb through other services to make sure passwords used on those sites aren't too similar to what they were using on Yahoo. And if they weren't doing so already, they'll have to treat everything they receive online with an abundance of suspicion, in case hackers are trying to trick them out of even more information.
The company said as much in an email to users that warned it was invalidating existing security questions - things like your mother's maiden name or the name of the street you grew up on - and asked users to change their passwords. Yahoo also said it was working with law enforcement in their investigation and encouraged people to change up the security on other online accounts and monitor those accounts for suspicious activity as well.
"The stolen Yahoo data is critical because it not only leads to a single system but to users' connections to their banks, social media profiles, other financial services and users' friends and family," said Alex Holden, the founder of Hold Security, which has been tracking the flow of stolen Yahoo credentials on the underground web. "This is one of the biggest breaches of people's privacy and very far-reaching."
Click to expand
(more...)
How to Protect Yourself After the Yahoo Attack Yahoo said on Thursday that hackers in 2014 stole the account information of at least 500 million users, including names, email addresses, telephone numbers, birth dates, passwords and, in some cases, security questions.
Even if you might not have used a Yahoo account for years, security experts say the incident could have far-reaching consequences for users beyond Yahoo's services.
Here are some answers to frequently asked questions about how you can protect yourself.
Click to expand
(more...)
[Link] Goldstein All-Star Member "You have sacrificed nothing and no one." 3689 Posts 8/10 Posted - Sep 24 2016 : 12:21PM
Hackers Trawl User Data in Hopes a Small Target Will Lead to a Big One SAN FRANCISCO - In disclosing that at least 500 million of its user accounts had been hacked, Yahoo blamed an unnamed "state-sponsored actor" for the intrusion. While Yahoo customers were caught by surprise, officials in Washington were not.
For more than a year, they had been getting warnings from threat researchers that hackers were targeting their personal Yahoo email. Even the accounts of their friends and family were in the cross hairs.
These days, intelligence and security experts say, nearly anyone can be the target of government-sponsored hackers.
By perusing the personal accounts of people with even the thinnest thread of a connection to power, hackers can unearth the occasional gold nugget, like the low-level Democratic operative whose private email correspondence, published online by hackers on Thursday, detailed the movements of Vice President Joseph R. Biden Jr. and Hillary Clinton and what appears to be Michelle Obama's passport. This expanded hacking strategy presents a new challenge: While top-secret material is usually kept in more secure computer systems, it is hard - if not impossible - to predict what information people are exchanging in personal email accounts. And it is even harder to know if hacking into one person's account can set off a cascading chain of events that could lead foreign spies to more useful information. In 2014, Yahoo also investigated attacks by Russian hackers that targeted dozens of private Yahoo accounts, one person with knowledge of Yahoo's investigation said, but it is not yet clear whether the same hackers were behind the larger hack.
"The Yahoo attack alone may not make sense, but when you combine the stolen data from Yahoo with other stolen data sets, it makes a lot more sense," said Sean Kanuck, the former national intelligence officer for online security issues at the Office of the Director of National Intelligence.
Hackers working on behalf of governments can match stolen Yahoo account data with their own material or information available on the criminal underground and published on the website WikiLeaks for a variety of purposes, Mr. Kanuck and other intelligence officials say.
Click to expand
At this point, they'd have a lot to work with. In the two years since Yahoo believes the hackers first penetrated its network, state-sponsored hackers have stolen tens of millions of records from the insurance companies Anthem and Premera Blue Cross, including Social Security numbers, health records, birth dates, addresses, emails, passwords and employment information - basically, everything you'd need to know about a person.
Hackers amassed a vast collection of security clearance records, even fingerprints, in a yearlong hacking of the United States Office of Personnel Management. They have breached law firms and accounting firms, and last year they even made off with flight records for millions of United Airlines passengers.
It may sound like a crazy collection of unrelated information. But it is not that difficult to make connections among seemingly random bits of information using data-sifting technology.
Just as a corporation may use big data to figure out what a consumer might buy based on their past purchases, a spy agency can use big data to make connections to useful intelligence. A Palo Alto, Calif., company named Palantir sells this technology to American intelligence agencies, allowing them, for example, to match travel records and personal data to identify possible terrorists.
Click to expand
So while Yahoo's announcement on Thursday that state-sponsored hackers - the company did not say what country it believes they are working for - had made off with more than 500 million customers' personal records was stunning to many, intelligence officials say it can be seen as just the latest step in an escalating nation-state digital warfare campaign.
"A lot of people overlook why some of these seemingly purposeless breaches matter," said Mr. Kanuck.
Intelligence services could use this information for a range of things - some trivial and some intrusive. They could match international flights taken by their own officials with those taken by American personnel to the same cities at the same time. They could comb the user names and emails released in a hacking of Ashley Madison, the online affairs site that was breached last year, with the personal Yahoo accounts of government officials and contractors or their spouses, and leak that information online or use it for blackmail.
And they can use the most intimate details of people's lives - their medical records - to undercut the reputations of prominent American athletes, as Russian hackers did in a release of medical records stolen from the World Anti-Doping Agency that belonged to the gymnast Simone Biles, the tennis stars Venus and Serena Williams and other Olympic athletes.
Click to expand
The biggest worry, Mr. Kanuck and other American intelligence officials say, is the impact these data thefts can have on global politics. James. R. Clapper, the director of National Intelligence, warned Senate officials earlier this year that Russia was escalating its espionage campaigns against United States targets.
"Russia continues to take information warfare to a new level, working to fan anti-U.S. and anti-Western sentiment both within Russia and globally," Mr. Clapper said in his annual worldwide threat briefing in February.
Intelligence officials and private security researchers say it's not just prominent United States government officials that Russian hackers are after. It's their spouses, staff members, lawyers, accountants and business partners, who may not have the same level of security on their data and communications.
"In the past year, we've seen personal webmail accounts and social network accounts specifically being targeted by Russian, Chinese and Iranian espionage operators, on several occasions," said John Hultquist, an espionage analysis manager at FireEye, the security software company. "That's where some of the most sensitive conversations take place, and hacking private accounts leaves a much lighter footprint."
Click to expand
One of the most adept at this approach, Mr. Hultquist and other security researchers say, has been a Russian intelligence hacking group alternately known in the security and intelligence community as APT28, Fancy Bear or Pawn Storm. The group regularly uses the compromised personal webmail accounts of staff members, spouses and their colleagues as tools to glean more information on high-level government targets.
In just the last few months, the group has been blamed for attacks on the Democratic National Committee, the White House and the World Anti-Doping Agency.
Going back to last year, the Russian group also has been trying to break into the online accounts of 2,600 members of the Washington elite - lobbyists, journalists, officials, contractors and even their spouses, according to private security researchers at Trend Micro, the global security company, who briefed intelligence agencies on the hacking.
Among the Russians' targets were Colin L. Powell, the former secretary of state, whose personal emails caused a sensation when they were leaked online last week, according to people with knowledge of the briefing who spoke on the condition of anonymity.
"This is the new normal," said Tom Kellermann, one of the security experts who briefed intelligence officials last year in his former role as chief security officer at Trend Micro. "It's not just the usual targets who are being hunted. It's their spouses." Click to expand
Mr. Kanuck said no one should be shocked that this is going on. "Every prominent person in Washington, every publicly known intelligence official, congressman and significant staffer should presume they have been targeted," Mr. Kanuck said. "You'd be a fool not to think that's the case."
Click to expand
Edited by - Goldstein on 9/24/2016 12:28:00 PM[Link]