← Yahoo

2013 breach (disclosed 2016) — all accounts

2013 3.0B records affected Share on X

Data compromised

Email addresses, Passwords (hashed), Names, Addresses, Session tokens, Session cookies

Technical writeup

State-sponsored actors stole data from every Yahoo user account in 2013. The breach included names, email addresses, hashed passwords (bcrypt, MD5, unsalted), and security Q&A. Yahoo did not detect the breach until 2016 and initially understated the scope.

Root cause

Cookie forgery allowed session hijacking without password; attackers gained persistent access and exfiltrated the entire user database.

References