People search Yahoo data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 11 Yahoo-linked incidents, with headline counts up to 3B+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Yahoo breach history matters
Yahoo operates in Technology (United States). Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2017 — — Yahoo: User accounts have been hacked using forged cookies…
Cataloged incident. Mar 2017. User accounts have been hacked using forged cookies to log in without a password over a 2 year period. BreachHistory cites approximately 32M+ affected records in this row. See the yahoo2017 and canonical BreachHistory entry.
2016 — — Yahoo: Happened in 2014, but no, 500.0M records
Cataloged incident. Sep 2016. Happened in 2014, but no. records stolen was originally thought to be much smaller. Yahoo revealed the real numbers in 2016. BreachHistory cites approximately 500M+ affected records in this row. See the yahoo2016 and canonical BreachHistory entry.
2016 — — Yahoo: Happened in 2013 but only disclosed late 2016, 1000.0M records
Cataloged incident. Happened in 2013 but only disclosed late 2016. Data included names, telephone numbers, DOBs, passwords and security questions. BreachHistory cites approximately 1B+ affected records in this row. See the yahoou and canonical BreachHistory entry.
2014 — 515K accounts (Russian state hack)
Cataloged incident. Russian state-sponsored hack. 500M+ global, 515K UK. Disclosed 2016. ICO fined £250K in 2018. Exposed categories include Names, emails, phones, passwords. BreachHistory cites approximately 515K+ affected records in this row. See the yahoo-uk2014 and canonical BreachHistory entry.
2014 — 500M accounts
Cataloged incident. State-sponsored actors stole data from at least 500 million Yahoo accounts in 2014. Data included names, emails, hashed passwords, and security Q&A. Disclosed alongside the 2013 breach. Exposed categories include Email addresses, Passwords (hashed), Names, Session cookies. BreachHistory cites approximately 500M+ affected records in this row. See the yho2 and canonical BreachHistory entry.
2013 — all accounts
Cataloged incident. State-sponsored actors stole data from every Yahoo user account in 2013. The breach included names, email addresses, hashed passwords (bcrypt, MD5, unsalted), and security Q&A. Yahoo did not detect the breach until 2016 and initially understated the scope. Exposed categories include Email addresses, Passwords (hashed), Names, Addresses, Session tokens, Session cookies. BreachHistory cites approximately 3B+ affected records in this row. See the gqwp and canonical BreachHistory entry.
2013 — — Yahoo: Happened in 2013 but only disclosed late 2016, 1000.0M records
Cataloged incident. Dec 2016. Happened in 2013 but only disclosed late 2016. Data included names, telephone numbers, DOBs, passwords and security questions. BreachHistory cites approximately 1B+ affected records in this row. See the yahoo2013 and canonical BreachHistory entry.
2013 — — Yahoo Japan: Hacking, 22,000,000 records
Cataloged incident. Data breach reported. tech organization. Method: hacked. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 22M+ affected records in this row. See the yahoo2013-22000000-wiki2 and canonical BreachHistory entry.
2012 — — Yahoo: Data breach reported, 500K records
Cataloged incident. Data breach reported. Reference: http://it.slashdot.org/story/12/07/12/1243217/nearly-half-a-million-yahoo-passwords-leaked-updated?utm_source=feedburnerGoogle+Reader&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29&utm_content=Google+Reader BreachHistory cites approximately 500K+ affected records in this row. See the yahoo2012 and canonical BreachHistory entry.
2012 — — Yahoo! Voices: Hacking, 450,000 records
Cataloged incident. Data breach reported. web organization. Method: hacked. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 450K+ affected records in this row. See the yahoo2012-450000-wiki2 and canonical BreachHistory entry.
2010 — — Yahoo: User accounts have been hacked using forged cookies…
Cataloged incident. User accounts have been hacked using forged cookies to log in without a password over a 2 year period. BreachHistory cites approximately 32M+ affected records in this row. See the yahoou2 and canonical BreachHistory entry.
Patterns and analysis
- Mixed intrusion and disclosure events — appears across multiple Yahoo catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Review OAuth app permissions and revoke unused third-party integrations.
- Step 5: Bookmark the Yahoo company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/yahoo · Latest: yahoo2017.
Sources: BreachHistory catalog (11 rows for Yahoo), company and regulator disclosures cited in individual breach records.