Breach report
Consumer TechYahoo
Every single Yahoo account was hacked - 3 billion in all
An August 2013 intrusion at Yahoo turned out to have touched every one of its roughly 3 billion user accounts, making it the largest known data breach in history and a costly problem for new owner Verizon.
Reported by CNN
Records exposed
3B
3 billion accounts
Scale vs. largest on file
- When
- 2013 (disclosed 2016, expanded 2017)
- How they got in
- Network intrusion (attacker never publicly identified)
- Sector
- Consumer Tech
In August 2013, an unidentified attacker broke into Yahoo's systems and walked away with records tied to the company's user accounts. Yahoo did not detect or disclose the theft for more than three years. When it finally announced the incident in December 2016, it put the damage at about 1 billion accounts. In October 2017, months after Verizon closed its purchase of Yahoo's core internet business, the company revised that figure to all 3 billion accounts that existed at the time, citing new intelligence gathered during the integration.
The stolen records covered names, email addresses, telephone numbers, dates of birth and passwords hashed with MD5, an outdated algorithm that offers little resistance to modern cracking. Some encrypted and unencrypted security questions and answers were also taken. Yahoo said plaintext passwords, payment card numbers and bank account details were not part of the haul. Accounts across Yahoo Mail, Flickr, Tumblr and Yahoo's fantasy sports products were affected. How the attacker got in has never been fully explained, and no one has been charged over the 2013 theft, unlike the separate 2014 breach that US prosecutors tied to Russian intelligence officers.
Because Yahoo had already forced password resets and invalidated unencrypted security questions after its 2016 disclosures, it said no further action was required from users when the count tripled. Critics argued that the delay between the theft and its disclosure left billions of people exposed to phishing and account takeover for years, especially those who reused their Yahoo passwords elsewhere.
The financial and legal consequences were significant. Verizon negotiated a $350 million reduction in the price of its roughly $4.5 billion acquisition after Yahoo's breaches came to light. Yahoo and its successor companies later agreed to a class-action settlement of about $117.5 million covering both the 2013 and 2014 incidents, and the case drew scrutiny from lawmakers in the United States and regulators abroad.
The Yahoo breach remains the benchmark for scale. It showed how legacy security choices such as weak password hashing can magnify a single intrusion, and how an undetected compromise can quietly grow into a liability that surfaces during an acquisition. For consumers, it underscored the value of unique passwords and multi-factor authentication on email accounts, which often serve as the master key for resetting every other online service.