Yahoo Inc.
ent_7720ca252f2d302f70d67c6a
Disclosures
3
State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
500,000,000
as filed · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Yahoo Inc.
- Normalized
- yahoo— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- yahooinc.com
Disclosure history (3)newest first
- 🐻California State AGas victim2016-12-14
Yahoo! Inc. disclosed a data breach affecting over 500 million user accounts. Unauthorized third parties stole data in August 2013, including names, emails, DOBs, hashed passwords, and security questions. A separate incident involved state-sponsored actors forging cookies in 2015-2016. Yahoo worked with law enforcement, forced password resets, invalidated security questions and forged cookies, and hardened systems. The incident is distinct from a September 2016 disclosure.
- 🦬Montana State AGas victim2016-09-22
YAHOO reported a data breach to the Montana Attorney General. The breach was reported on 2016-09-22. The breach occurred from 9/1/2014 to 10/1/2014.
- 🐻California State AGas victim2016-09-22
In late 2014, Yahoo! Inc. suffered a state-sponsored intrusion in which account information for at least 500 million users was stolen. Compromised data included names, email addresses, phone numbers, dates of birth, hashed passwords, and security questions/answers. The breach was publicly disclosed on September 22, 2016. No payment card or bank account data was affected.