True crime news logo
  • News

Sign up for our newsletter and get the latest stories

Never miss the latest true crime news, reviews and top lists — plus new podcasts, series, films and books.

You can unsubscribe with one click from any email.

True crime news logo

The international true crime destination. Cases, documentaries, podcasts and travel routes.

© 2026 truecrime.news. All rights reserved.

Sagsmappe

Yahoo's 3 Billion Account Breach: History's Largest Hack

How two massive data breaches exposed personal information from nearly half the world's internet users — and went undetected for years

Mappe Åbnet: JUNE 6, 2025 AT 09:59 AM
A computer screen displaying a Yahoo login page with a small sticky note that reads "Password Breach" placed nearby, suggesting a breach into user accounts.
BEVIS

Sagsdetaljer

Quick Facts

Klassifikation:

Data breach
Espionage
Hacking
Scandal
USA
Crypto
Internet

Quick Facts

LocationSan Francisco, USA

In August 2013, Yahoo suffered a catastrophic security breach that would eventually be confirmed as the largest data breach in history. Hackers gained access to approximately 3 billion user accounts—nearly half of all internet users at the time. The company would not publicly acknowledge this breach until December 2016, more than three years later.

But Yahoo's security failures didn't end there. Between November and December 2014, a second massive breach compromised roughly 500 million additional user accounts. This breach was disclosed publicly in September 2016, a full two years after it occurred.

## What Was Stolen

Both breaches exposed the same categories of sensitive personal information: names, email addresses, phone numbers, and dates of birth. Hackers also obtained hashed and encrypted passwords, along with security questions in both encrypted and unencrypted formats. For millions of Yahoo users, this meant their most basic identity information was in the hands of criminals or foreign actors.

## The Investigation and Attribution

The two breaches appear to have had different perpetrators. The 2014 breach was officially attributed by the U.S. Justice Department to Alexey Belan, a Russian national accused of orchestrating the attack. However, the much larger 2013 breach remains officially unresolved. When Yahoo CEO Marissa Mayer testified before Congress in 2017, she stated that the company could not determine who was responsible for the 2013 breach. Intelligence assessments suggest state-sponsored actors were likely involved in at least one of the incidents, though no definitive attribution has been made public.

Identity theft
Fbi
Digital evidence
Terror
Corruption
justitssvigt
justitsmordet
hvidvaskning
cybersikkerhed
mordsager
mordssag
overerstatningskommission
domstol
kryptovaluta
mordsag
Sagsstatus
Løst
Sted
San Francisco, USA

## Delayed Disclosure and Consequences

Yahoo's three-year delay in disclosing the 2013 breach proved costly. The Securities and Exchange Commission fined the company $35 million for failing to promptly inform investors about the security incident. The breach also became a major factor in the company's acquisition by Verizon. Originally valued at $4.8 billion, Verizon reduced its offer by $300 million—citing the data breaches as the reason—bringing the final purchase price to $4.5 billion.

The financial damage extended beyond the acquisition. Forty-one class-action lawsuits were filed against Yahoo by affected users seeking compensation for the exposure of their personal data.

## A Pattern of Failures

What made the Yahoo breaches particularly significant wasn't just their scale, but what they revealed about corporate cybersecurity practices. The fact that the 2013 breach went undetected and undisclosed for over three years raised serious questions about Yahoo's security monitoring capabilities and its obligation to users. The subsequent 2014 breach, occurring while the 2013 breach remained hidden, suggested systemic vulnerabilities in the company's infrastructure.

When the truth finally emerged in 2016, it shocked the cybersecurity world. The breach toll of 3 billion accounts surpassed previous record holders and underscored how vulnerable even major technology companies could be to sophisticated hacking operations.

## Sources

https://www.ecpi.edu/blog/yahoo-hack-worse-than-expected-3-billion-accounts-compromised

https://www.barclaysimpson.com/yahoo-admits-2013-breach-hit-all-3-billion-users/

https://www.huntress.com/threat-library/data-breach/yahoo-data-breach

https://cybersecurityventures.com/yahoo-still-ranks-as-the-largest-data-breach-in-history/

Read more

A compromised Microsoft Exchange server displays a terminal screen filled with cryptic code, cables snaking out as a technician in the background examines the setup, symbolizing the widespread impact of the 2021 Hafnium cyberattack.
Case

Chinese State Hackers Breached Thousands via Microsoft Exchange

A Starwood-branded server room with tangled Ethernet cables and a laptop displaying a web shell interface, symbolizing the vulnerability exploited in Marriott's data breach affecting 500 million guests
Case

Marriott's Massive Breach: 383 Million Guests Exposed

A computer screen displaying the WannaCry ransomware message, with Bitcoin symbols and a countdown timer, amid a chaotic office with disorganized NHS documents under flickering fluorescent lights.
Case

WannaCry: The Ransomware Attack That Crippled the NHS

Related Content
A compromised Microsoft Exchange server displays a terminal screen filled with cryptic code, cables snaking out as a technician in the background examines the setup, symbolizing the widespread impact of the 2021 Hafnium cyberattack.

Chinese State Hackers Breached Thousands via Microsoft Exchange

A Starwood-branded server room with tangled Ethernet cables and a laptop displaying a web shell interface, symbolizing the vulnerability exploited in Marriott's data breach affecting 500 million guests

Marriott's Massive Breach: 383 Million Guests Exposed

A computer screen displaying the WannaCry ransomware message, with Bitcoin symbols and a countdown timer, amid a chaotic office with disorganized NHS documents under flickering fluorescent lights.

WannaCry: The Ransomware Attack That Crippled the NHS

A computer screen displaying a terminal with lines of code, a reflection showing a faint Amazon logo, symbolizing the Twitch 2021 leak exposé of streamers' earnings and Amazon's unreleased projects.

Twitch Breach Exposed Top Streamers' Million-Dollar Payouts

Advertisement
SS

Susanne Sperling

View all stories →
Share this post: