BOSTON – Yahoo has tripled down on what was already the largest data breach in history, saying it affected all 3 billion accounts on its service, not the 1 billion it revealed late last year.
The company announced Tuesday that it’s providing notice to additional user accounts affected by the August 2013 data theft.
The breach was previously disclosed by the company in December . The stolen information included names, email addresses, phone numbers, birthdates and security questions and answers.
Following its acquisition by Verizon in June, Yahoo says, it obtained new intelligence while investigating the breach with help from outside forensic experts. It says the stolen customer information did not include passwords in clear text, payment card data or bank account information.
Every single Yahoo account was hacked in August 2013 — 3 billion in all, Yahoo parent company Verizon said https://t.co/U1YuZe9e5M pic.twitter.com/uSRpgANTlf
— CNN (@CNN) 3 de octubre de 2017
Yahoo had already required users to change their passwords and invalidate security questions so they couldn’t be used to hack into accounts.
“Whether it’s 1 billion or 3 billion is largely immaterial. Assume it affects you,” said Sam Curry, chief security officer for Boston-based firm Cybereason. “Privacy is really the victim here.”
The disclosure is also a huge embarrassment for Verizon, which has just started running TV ads for its new subsidiary Oath, which will consist of Yahoo and AOL services.
MATT O’BRIEN