Skip to main content

Yahoo is warning users over state-sponsored cookie-forging attacks

us charges russian yahoo hackers 1
New Yorker
Yahoo’s security woes continue with the company sending out a fresh warning to users over hacked accounts at the hands of allegedly state-sponsored actors.

In an email to users, Yahoo said it has identified evidence of cookie-forging attacks on some accounts, which would allow attackers to access an account without re-entering a password. The email was only sent to accounts that Yahoo believes have been affected by these intrusion attempts so we don’t know how many people have been impacted.

“Our outside forensic experts have been investigating the creation of forged cookies that could allow an intruder to access users’ accounts without a password,” the email reads. “Based on the ongoing investigation, we believe a forged cookie may have been used in 2015 or 2016 to access your account.”

It is believed that hackers obtained Yahoo’s source code for creating cookies. The company’s forensics team has invalidated any corrupted cookies it found.

It’s not clear what evidence Yahoo has to suggest these cookie forging attempts were state-sponsored. However, Yahoo has been the victim of at least two major hacks that were disclosed in the last few months for which it pointed the finger at possible hackers acting on behalf of a government.

The numerous data breaches at the web firm included 500 million accounts compromised in 2014 and up to 1 billion accounts compromised in 2013. But it wasn’t until last year that these mega breaches — as they’ve been dubbed — came to light. Yahoo is now currently under investigation by the Securities and Exchange Commission over why it waited years before disclosing the details of the hacks.

The security blunders could be costly for Yahoo as Verizon, its purchaser, has since sought a price tag reduction between $250 million and $350 million (off the original $4.83 billion offer), as it was unaware of these breaches when the offer was made.

Editors' Recommendations

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
How to customize mouse gestures on Mac
Apple Magic Mouse on a desk.

Did you know that you can still pull off gestures and haptic tricks with a Mac computer, even without a touchscreen? Such feats are possible, just as long as you own an Apple Magic Mouse. Far more than a sleek-looking desk accessory, the Magic Mouse functions much like a MacBook trackpad. Taps, long presses, swipes, and pinches (among other actions) deliver a number of results, and you’ll be able to customize these commands, too.

Read more
How to delete or hide chats in Microsoft Teams
Running Microsoft Teams on the Galaxy Tab S8.

Microsoft Teams is a terrific workplace platform for keeping the camaraderie strong. Featuring collaborative messaging, video conferencing, and file-sharing tools, it’s your one-stop-shop for in-office, hybrid and at-home workers alike. But anyone with a long history of using Teams will tell you how clogged up your message stockpile can get. Fortunately, deleting and hiding these exchanges is relatively easy to do, and we’ve put together this guide to help.

Read more
Why Llama 3 is changing everything in the world of AI
Meta AI on mobile and desktop web interface.

In the world of AI, you've no doubt heard about what OpenAI and Google have been up to. And now, Meta's Llama LLM (large language model) is becoming an increasingly important player in the game, especially with its open-source nature. Meta recently made a big splash with the launch of its Llama 3 AI model, and it's shaken up the field dramatically.

The reasons why are multiple and varied. It's free to use, it has a wide user base, and yes, it's open source, to name but a few. Here's why Llama 3 is taking the AI industry by storm and may shape its future for some time to come.
Llama 3 is really good
We can debate until the cows come home about how useful AIs like ChatGPT and Llama 3 are in the real world -- they're not bad at teaching you board game rules -- but the few benchmarks we have for how capable these AI are give Llama 3 a distinct advantage.

Read more