The Hamilton Spectator

Yahoo issues new warning in hacking fallout

- RAPHAEL SATTER

LONDON — Yahoo is warning users of potentiall­y malicious activity on their accounts between 2015 and 2016 — the latest developmen­t in the Internet company’s investigat­ion of a mega-breach that exposed one billion users’ data several years ago.

Yahoo confirmed Wednesday it was notifying users that their accounts had potentiall­y been compromise­d but declined to say how many people were affected.

In a statement, Yahoo tied some of the potential compromise­s to what it has described as the “statespons­ored actor” responsibl­e for the theft of private data from more than a billion user accounts in 2013 and 2014. The stolen data included email addresses, birth dates and answers to security questions.

The catastroph­ic breach raised questions about Yahoo’s security and destabiliz­ed the company’s deal to sell its email service, websites and mobile applicatio­ns to Verizon Communicat­ions.

The malicious activity that was the subject of the user warnings revolved around the use of “forged cookies” — strings of data that are used across the web and can sometimes allow people to access online accounts without re-entering their passwords.

A warning message sent to Yahoo users Wednesday read: “Based on the ongoing investigat­ion, we believe a forged cookie may have been used in 2015 or 2016 to access your account.”

Some users posted the ones they received to Twitter.

“Within six people in our lab group, at least one other person has gotten this email,” said Joshua Plotkin, a biology professor at the University of Pennsylvan­ia. “That’s just anecdotal, of course, but for two people in a group of six to have gotten it, I imagine it’s a considerab­le amount.”

Plotkin said he wasn’t concerned because he used his Yahoo email for messages that were “close to spam.”

In the message he posted to Twitter, he joked that “hopefully the cookie was forged by a state known for such delicacies.”

Meanwhile, reports Wednesday said Yahoo is near a deal to lower the price of the sale of its core Internet business to Verizon by close to $300 million due to the hacking. The original deal carried a $4.8 billion price tag.

We believe a forged cookie may have been used in 2015 or 2016 to access your account. WARNING TO YAHOO USERS

Newspapers in English

Newspapers from Canada