---
title: "Cybersecurity Scary Stories: Hacking Yahoo - EMPIST®"
description: What happens when a bump in the night turns into billions of exposed accounts? Let the hacking of Yahoo be a warning to us all.
image: https://hs.empist.com/hubfs/Imported_Blog_Media/Cybersecurity-Scary-Stories-NoCopy-1.jpg
---

[Skip to main content](https://hs.empist.com/blog/cybersecurity-scary-stories-hacking-yahoo#main-content)

[![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png) ![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png) ![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png) ![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png)](https://hs.empist.com/home)

- [Show submenu for IT Services IT Services](https://hs.empist.com/it-services/) 
    - [Managed IT Services](https://hs.empist.com/it-managed-services)
    - [Co-Managed IT](https://hs.empist.com/co-managed-it)
- [Cybersecurity Services](https://hs.empist.com/cybersecurity)
- [Cloud Services](https://hs.empist.com/cloud-services-managed-private-public-hybrid)
- [Show submenu for Why EMPIST Why EMPIST](https://empist.com/about-us/) 
    - [Blog](https://hs.empist.com/blog)
- [Show submenu for Support Support](https://empist360.com) 
    - [Status](https://status.empist.com)

Open main navigation

Close main navigation

- Show submenu for IT Services  IT Services 
  
    - IT Services
    - [IT Services](https://hs.empist.com/it-services/)
    - [Managed IT Services](https://hs.empist.com/it-managed-services)
    - [Co-Managed IT](https://hs.empist.com/co-managed-it)
- [Cybersecurity Services](https://hs.empist.com/cybersecurity)
- [Cloud Services](https://hs.empist.com/cloud-services-managed-private-public-hybrid)
- Show submenu for Why EMPIST  Why EMPIST 
  
    - Why EMPIST
    - [Why EMPIST](https://empist.com/about-us/)
    - [Blog](https://hs.empist.com/blog)
- Show submenu for Support  Support 
  
    - Support
    - [Support](https://empist360.com)
    - [Status](https://status.empist.com)
- [Under Attack?](https://empist.com/under-attack/)
  
  [Call Now](tel:+13123601900)

[Under Attack?](https://empist.com/under-attack/)

[Call Now](tel:+13123601900)

[Blog](https://hs.empist.com/blog)

Tags

- [Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)
- [IT Services](https://hs.empist.com/blog/tag/it-services)
- [News](https://hs.empist.com/blog/tag/news)
- [Digital Agency](https://hs.empist.com/blog/tag/digital-agency)
- [Cloud Services](https://hs.empist.com/blog/tag/cloud-services)
- [Business](https://hs.empist.com/blog/tag/business)
- [Business Intelligence](https://hs.empist.com/blog/tag/business-intelligence)

Search

- [Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)
- [IT Services](https://hs.empist.com/blog/tag/it-services)
- [News](https://hs.empist.com/blog/tag/news)
- [Digital Agency](https://hs.empist.com/blog/tag/digital-agency)
- [Cloud Services](https://hs.empist.com/blog/tag/cloud-services)
- [Business](https://hs.empist.com/blog/tag/business)
- [Business Intelligence](https://hs.empist.com/blog/tag/business-intelligence)

What happens when a bump in the night turns into billions of exposed accounts? Let the hacking of Yahoo be a warning to us all. 

An online stalwart. A digital kingpin. A search giant. Pioneering the early internet, what started as a simple database in 1994 quickly expanded to become the library of web services we now know as Yahoo. Offering search capabilities, mail, news, and even an ad platform, there was a time when it would seem Yahoo was too big to fail. 

Was, being the operative word. Like many companies before it ([and surely many more to come](https://empist.com/cybersecurity-scary-stories-colonial-pipeline/)) Yahoo neglected to heed the warnings of [cybersecurity experts](https://empist.com/it-services/managed-services/cybersecurity/), leaving the company and *all *its user data defenseless from attack.  

**And attack they did. Twice.  **

[According to Yahoo themselves](https://help.yahoo.com/kb/SLN27925.html), the first major hit on Yahoo servers took place in mid-2013. Evidence of the exceptionally large data breach was uncovered in 2016 while parsing through data of an entirely different, yet smaller, cyberattack (more on that later). Within this data, agents found a 2015 listing on the dark web offering information on nearly 1 billion Yahoo [user accounts to the tune of $300,000.](https://www.nytimes.com/2016/12/15/technology/hacked-yahoo-data-for-sale-dark-web.html)

The [specific account information exposed](https://help.yahoo.com/kb/SLN27925.html) included unencrypted security questions and answers as well as encrypted names, email addresses, and [passwords](https://empist.com/how-do-i-remember-my-complicated-passwords/). Many experts agree that the type of encryption used was out of date and easily hackable. So, because folks so regularly reuse account information, this breach immediately put all of the victims’ other accounts at risk as well.

Once discovered, Yahoo reported the breach and notified all affected users. But the damage was not yet done. Upon further investigation in 2017, Yahoo officials revealed that their original estimate of 1 billion accounts compromised was far too low.  

The real number? **[Over 3 billion –which amounts to nearly every single account Yahoo had at the time.](https://www.npr.org/sections/thetwo-way/2017/10/03/555016024/every-yahoo-account-that-existed-in-mid-2013-was-likely-hacked) To this day, the 2013 Yahoo hack is the largest known data breach in history, the exact source of which *still* hasn’t been found. ** 

To add insult to injury, as news of the breach above was unfolding, Yahoo [was still recovering from revelations of a smaller attack from 2014 as well](https://help.yahoo.com/kb/sln28092.html). Believed to be a state-sponsored attack, this hack leveraged poor cookie management to enter users’ accounts, bypassing password protection. By the time it was officially discovered in 2016, over 500 million accounts were exposed. Eventually, the United States government [would try Russian agents and affiliated “hackers for hire”](https://www.justice.gov/opa/video/us-charges-russian-fsb-officers-their-criminal-conspirators-hacking-yahoo-millions-email#:~:text=A%20grand%20jury%20in%20the,access%20Yahoo's%20network%20and%20the) with crimes for the attack.  

Just wait, it gets even worse.  

In March of 2017, an internal investigation by Yahoo found that the company’s security team, execs, and some legal staff [actually knew of the attack in 2014](https://www.nytimes.com/2016/11/10/technology/yahoo-employees-knew-in-2014-about-hacker-attack.html), before it was officially reported two years later. According to a [regulatory filing with the SEC](https://www.sec.gov/Archives/edgar/data/1011006/000119312517065791/d293630d10k.htm), senior members of Yahoo’s team did not act sufficiently with their knowledge. Following this bombshell, Yahoo’s top lawyer resigned without severance and [CFO Marissa Mayer lost her 2016 bonus](https://www.npr.org/sections/thetwo-way/2017/03/02/518089196/yahoo-ceo-marissa-mayer-loses-bonus-and-stock-award-over-security-breach#:~:text=18%2C%202016.,-Eric%20Risberg%2FAP&text=CEO%20Marissa%20Mayer%20will%20not,were%20mishandled%20by%20senior%20executives.), later resigning when Verizon bought Yahoo [at an](https://techcrunch.com/2017/02/21/verizon-knocks-350m-off-yahoo-sale-after-data-breaches-now-valued-at-4-48b/) understandably discounted price.  

**A truly chilling saga, isn’t it? **

While Yahoo is, of course, still up-and-running today, it has nowhere near the market share it once enjoyed. With the specter of multiple, history-making data breaches hanging overhead much of the company’s reputation – and once-valued customers – have been lost to other web service providers.  

Which begs the question: if an enterprise as large as Yahoo could suffer such devastating effects at the hands of cybercriminals, [what’s stopping them from heading after ](https://empist.com/do-i-need-to-worry-about-ransomware/)*you*? And if the hack of 3 billion accounts could go unnoticed for nearly three years, who’s to say they haven’t already?  

It’s a terrifying thought, but you don’t have to take it alone. [Protecting your sensitive information](https://empist.com/it-services/managed-services/cybersecurity/) is more important today than ever before; EMPIST is here to help. Learn more about our cybersecurity services by contacting team EMPIST [online today.](https://empist.com/contact/)  

(Additional Sources: [CNN Business](https://money.cnn.com/2017/10/03/technology/business/yahoo-breach-3-billion-accounts/index.html), [New York Times](https://www.nytimes.com/2016/12/14/technology/yahoo-hack.html), [NPR,](https://www.npr.org/sections/thetwo-way/2017/10/03/555016024/every-yahoo-account-that-existed-in-mid-2013-was-likely-hacked)[Tech Crunch,](https://techcrunch.com/2017/02/21/verizon-knocks-350m-off-yahoo-sale-after-data-breaches-now-valued-at-4-48b/)[Yahoo](https://help.yahoo.com/kb/sln28092.html))

Tags:

[Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)

![EMPIST - Symbol](https://hs.empist.com/hs-fs/hubfs/EMPIST%20Branding/EMPIST%20-%20Symbol.png?width=96&height=106&name=EMPIST%20-%20Symbol.png)

### Got A Question?

Feel free to contact us with any questions about this post or anything else you may be interested in finding out.

###### Categories

- [Cybersecurity](https://hs.empist.com/blog/tag/cybersecurity)
- [IT Services](https://hs.empist.com/blog/tag/it-services)
- [News](https://hs.empist.com/blog/tag/news)
- [Digital Agency](https://hs.empist.com/blog/tag/digital-agency)
- [Cloud Services](https://hs.empist.com/blog/tag/cloud-services)

###### Recent Posts

- [What Every Business Needs to Know About Ransomware Protection](https://hs.empist.com/blog/what-every-business-needs-to-know-about-ransomware-protection)
- [How to Choose the Right IT Support Model for Your Business](https://hs.empist.com/blog/how-to-choose-the-right-it-support-model-for-your-business)
- [Hidden Risks of Shadow IT and How to Mitigate Them](https://hs.empist.com/blog/hidden-risks-of-shadow-it-and-how-to-mitigate-them)
- [What Small Business Owners Should Know About Network Security](https://hs.empist.com/blog/what-small-business-owners-should-know-about-network-security)
- [5 Ways Co-Managed IT Services Can Boost Your Team’s Efficiency](https://hs.empist.com/blog/5-ways-co-managed-it-services-can-boost-your-teams-efficiency)

## Related Articles

[![What Every Business Needs to Know About Ransomware Protection](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0703_WistiaBlogThumbnail.jpg?width=500&height=500&name=0703_WistiaBlogThumbnail.jpg) What Every Business Needs to Know About Ransomware Protection Marty Hitzeman • Jul 3, 2026, 4:00:01 AM](https://hs.empist.com/blog/what-every-business-needs-to-know-about-ransomware-protection)

[![What Small Business Owners Should Know About Network Security](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0612WistiaBlogThumbnail.jpg?width=500&height=500&name=0612WistiaBlogThumbnail.jpg) What Small Business Owners Should Know About Network Security Marty Hitzeman • Jun 12, 2026, 4:00:51 AM](https://hs.empist.com/blog/what-small-business-owners-should-know-about-network-security)

[![Healthcare IT: Risk Management and Compliance Tips](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0515WistiaBlogThumbnail.jpg?width=500&height=500&name=0515WistiaBlogThumbnail.jpg) Healthcare IT: Risk Management and Compliance Tips Marty Hitzeman • May 15, 2026, 4:00:05 AM](https://hs.empist.com/blog/healthcare-it-risk-management-and-compliance-tips)

[![Securing Hybrid Cloud Environments: Best Practices for SMBs](https://hs.empist.com/hs-fs/hubfs/Imported_Blog_Media/0424_WistiaBlogThumbnail.jpg?width=500&height=500&name=0424_WistiaBlogThumbnail.jpg) Securing Hybrid Cloud Environments: Best Practices for SMBs Marty Hitzeman • Apr 24, 2026, 4:00:05 AM](https://hs.empist.com/blog/securing-hybrid-cloud-environments-best-practices-for-smbs)

[![empist\_logo](https://hs.empist.com/hs-fs/hubfs/AzureWebAppFiles/empist_logo.png?width=271&height=50&name=empist_logo.png)](https://empist.com)

- [MANAGED IT SERVICES](https://hs.empist.com/it-managed-services)
- [CYBERSECURITY](https://hs.empist.com/cybersecurity)
- [CLOUD SERVICES](https://hs.empist.com/cloud-services-managed-private-public-hybrid)
- [CO-MANGED IT](https://hs.empist.com/co-managed-it)
- [PROFESSIONAL IT SERVICES](https://empist.com/it-services/professional-it-services)
- [BUSINESS PROCESS IMPROVEMENT](https://empist.com/it-services/business-process-improvement)
- [DIGITAL SERVICES](https://empist.com/it-services/digital-services)
- [SUPPORT](https://empist360.com)

EMPIST, LLC 2026 Copyright. All rights reserved.  [Privacy policy](https://empist.com/privacy-policy/) | [Terms](https://empist.com/terms-conditions-us/)

- <https://www.facebook.com/empist/>
- <https://www.instagram.com/empistgroup/>
- <https://www.linkedin.com/company/empist/>
- <https://www.youtube.com/@EMPIST>
- <https://twitter.com/Empist>
- <http://tiktok.com/@empist>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Christina Tzouganatos",
    "url" : "https://hs.empist.com/blog/author/christina-tzouganatos"
  },
  "dateModified" : "2026-02-02T16:03:54.036Z",
  "datePublished" : "2021-10-04T14:43:11.000Z",
  "headline" : "Cybersecurity Scary Stories: Hacking Yahoo - EMPIST®",
  "image" : [ "https://hs.empist.com/hubfs/Imported_Blog_Media/Cybersecurity-Scary-Stories-NoCopy-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://hs.empist.com/blog/cybersecurity-scary-stories-hacking-yahoo",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://hs.empist.com/hubfs/Empist_logo_dark-1.png"
    },
    "name" : "EMPIST"
  }
}
```