2013 breach (disclosed 2016) — all accounts
Data compromised
Email addresses, Passwords (hashed), Names, Addresses, Session tokens, Session cookies
Technical writeup
State-sponsored actors stole data from every Yahoo user account in 2013. The breach included names, email addresses, hashed passwords (bcrypt, MD5, unsalted), and security Q&A. Yahoo did not detect the breach until 2016 and initially understated the scope.
Root cause
Cookie forgery allowed session hijacking without password; attackers gained persistent access and exfiltrated the entire user database.