Yahoo’s 2016 breach announcements described separate incidents, not one attack: a late-2014 theft affecting about 500 million accounts and an August 2013 theft initially estimated at more than one billion. Verizon later revised the 2013 figure to all 3 billion Yahoo accounts. A separate cookie-forging method let attackers access some accounts without entering their passwords.
Why are there different numbers for the Yahoo breach?
Yahoo made two major breach disclosures in 2016. Its September 22 announcement covered a late-2014 theft affecting approximately 500 million accounts. Its December 14 announcement covered a separate August 2013 theft, which Yahoo then estimated had affected more than one billion accounts.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Big Breaches: Cybersecurity Lessons for Everyone | $15.86 | Buy on Amazon |
| 2 |
|
Data Breaches: Case Studies of Corporate Catastrophes | $6.49 | Buy on Amazon |
In October 2017, Verizon revised the 2013 incident’s scope: it affected all 3 billion Yahoo accounts. That was a later revision, not the figure Yahoo gave in its December 2016 notice. The 500 million figure belongs to the separate 2014 incident.
| Incident | Intrusion period | First public disclosure | Account scope reported | What the figures mean |
|---|---|---|---|---|
| 2014 theft | Late 2014 | September 22, 2016 | Approximately 500 million | Yahoo’s 2016 estimate for this incident; also cited in Yahoo’s SEC filings and the DOJ’s account of the broader conspiracy. |
| 2013 theft | August 2013 | December 14, 2016 | More than one billion initially; later revised to all 3 billion Yahoo accounts | Yahoo’s initial estimate was announced in 2016. Verizon disclosed the all-3-billion revision in 2017. |
| Forged-cookie activity | Identified in 2015 and 2016 | Discussed in Yahoo’s December 2016 announcement and later SEC reporting | Approximately 32 million accounts with forged-cookie activity | A separate authentication method, not another account-count estimate for either theft. |
Yahoo’s SEC filings treated the 2013 and 2014 thefts as distinct security incidents. The forged-cookie activity is related to the wider intrusion story but should not be confused with either incident’s account-scope estimate.
#1 Best Overall
What information did the attackers take?
Late-2014 incident
Yahoo said the stolen account information included names, email addresses, telephone numbers, dates of birth, and hashed passwords. For some accounts, attackers also obtained security questions and answers, which could be encrypted or unencrypted. Yahoo’s SEC filing said the affected system did not contain payment-card data or bank-account information.
Yahoo reported hashed passwords, not plaintext passwords, for this incident. The available account of the breach does not establish that payment-card or bank-account information was stolen from the affected system.
August-2013 incident
Yahoo’s December 2016 announcement described account information stolen in the 2013 intrusion, while Verizon’s later revision established that the incident affected all 3 billion Yahoo accounts. The cited material does not provide a complete, account-by-account inventory of the information taken in that incident, so its data categories should not be assumed to be identical to those reported for the 2014 theft.
How did forged cookies let attackers bypass passwords?
A password is one way to prove that a user may access an account. A browser authentication cookie is another: after a successful sign-in, a service may use the cookie to recognize that browser without asking for the password again. The DOJ alleged that the attackers stole a copy of Yahoo’s User Database and gained access to its Account Management Tool. With that access, they could create forged authentication cookies for selected accounts.
A forged cookie could make Yahoo treat an attacker’s browser as already authenticated, bypassing password entry for that account. According to the DOJ, at least 6,500 accounts were accessed using this method. Yahoo and SEC reporting put the number of accounts associated with forged-cookie activity at approximately 32 million; that figure is not the number the DOJ said was accessed through the method in its charged case.
The DOJ described the broader conspiracy as using stolen information from at least 500 million Yahoo accounts. Its 2017 statement said the defendants used unauthorized access to Yahoo’s systems to steal information from about at least 500 million accounts. That statement should not be read as changing the separate 2013 incident’s later, all-3-billion-account scope.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Who was behind the attack, and who was targeted?
The DOJ and FBI charged two Russian Federal Security Service (FSB) officers and two criminal hackers in connection with the Yahoo intrusion. DOJ materials identify Dmitry Dokuchaev, Igor Sushchin, and Alexsey Belan among those described in the case.
According to the DOJ and FBI, targets included Russian and U.S. government officials, journalists, and people in the private sector. These are allegations described in the criminal case; they do not mean every affected Yahoo account belonged to a targeted individual.
Free tools Windows power users keep installed
One-click scans. No signup required.
When did Yahoo disclose the incidents, and what did it do?
- September 22, 2016: Yahoo announced the late-2014 theft affecting approximately 500 million accounts and advised users to change Yahoo passwords, change reused or similar credentials on other accounts, invalidate forged cookies, and review credit reports.
- December 14, 2016: Yahoo announced the separate August-2013 theft, then estimated to affect more than one billion accounts, and discussed forged cookies identified in 2015 and 2016.
- 2017: Yahoo’s 2016 Form 10-K reported that an independent committee concluded the information-security team had contemporaneous knowledge of the 2014 compromise and related cookie-forging activity. The filing also recorded $16 million in security-incident expenses in 2016. Verizon later revised the 2013 incident’s scope to all 3 billion Yahoo accounts.
Yahoo’s September 2016 notice specifically urged users to change passwords and security questions and answers on other accounts where they had used the same or similar credentials. That advice addressed the risk that someone could reuse exposed information beyond Yahoo; it did not imply that all those other services had been breached.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

