This article is from the source 'bbc' and was first published or seen on . It last changed over 40 days ago and won't be checked again for changes.

You can find the current article at its original source at http://www.bbc.co.uk/news/world-us-canada-37447016

The article has changed 13 times. There is an RSS feed of changes available.

Version 10 Version 11
Yahoo 'state' hackers stole data from 500 million users Yahoo 'state' hackers stole data from 500 million users
(about 5 hours later)
Yahoo says "state-sponsored" hackers stole information from about 500 million users in what appears to be the largest publicly disclosed cyber-breach in history. Yahoo says "state-sponsored" hackers stole data on about 500 million users in what could be the largest publicly disclosed cyber-breach in history.
The breach included swathes of personal information, including names and emails, as well as “unencrypted security questions and answers”.The breach included swathes of personal information, including names and emails, as well as “unencrypted security questions and answers”.
The hack took place in 2014 but has only now been made public.The hack took place in 2014 but has only now been made public.
The FBI has confirmed it is investigating the claims. In the UK it is believed data on about eight million user accounts was taken in the hack.
Stolen data includes names, email addresses, telephone numbers, dates of birth and encrypted passwords, but not credit card data, Yahoo said.Stolen data includes names, email addresses, telephone numbers, dates of birth and encrypted passwords, but not credit card data, Yahoo said.
It said the information was "stolen by what we believe is a state-sponsored actor" but did not say which country it held responsible.It said the information was "stolen by what we believe is a state-sponsored actor" but did not say which country it held responsible.
The FBI has confirmed it is investigating the claims.
Password change urgedPassword change urged
News of a possible major attack on the technology firm emerged in August when a hacker known as "Peace" was apparently attempting to sell information on 200 million Yahoo accounts.News of a possible major attack on the technology firm emerged in August when a hacker known as "Peace" was apparently attempting to sell information on 200 million Yahoo accounts.
On Thursday, Yahoo confirmed the breach was far bigger than first thought.On Thursday, Yahoo confirmed the breach was far bigger than first thought.
Yahoo is recommending all users should change their passwords if they have not done so since 2014.Yahoo is recommending all users should change their passwords if they have not done so since 2014.
In the UK, ISPs Sky and BT issued warnings for customers that they may be affected by the breach as Yahoo provides email services for both ISPs. Sky advised all its customers to change their passwords as Yahoo is behind all Sky.com email accounts. In the UK, ISPs Sky and BT issued warnings for customers that they may be affected by the breach as Yahoo provides email services for both ISPs.
Sky estimates that it had about 2.5 million Sky.com email account holders at the time of the breach. It said not all were affected but would advise everyone with a Sky.com email account to update their password.
BT said it was carrying out its own investigation but advised the "minority" of its customers who use Yahoo mail to change their passwords.BT said it was carrying out its own investigation but advised the "minority" of its customers who use Yahoo mail to change their passwords.
Questions for Yahoo - Dave Lee, BBC North America technology reporter, San FranciscoQuestions for Yahoo - Dave Lee, BBC North America technology reporter, San Francisco
The nature of the information stolen feels somewhat run-of-the-mill - no payment info, and passwords were encrypted. Good. But the chain of events leading up to this unprecedented announcement gives rise to some incredibly pressing questions for Yahoo.The nature of the information stolen feels somewhat run-of-the-mill - no payment info, and passwords were encrypted. Good. But the chain of events leading up to this unprecedented announcement gives rise to some incredibly pressing questions for Yahoo.
Why did it take so long to confirm the hack and its scale? Why did it take so long to tell users and prompt them to protect themselves?Why did it take so long to confirm the hack and its scale? Why did it take so long to tell users and prompt them to protect themselves?
State-sponsored attacks are typically for political, not financial gain. So why were details reportedly being sold online? What evidence is there that it was state-sponsored?State-sponsored attacks are typically for political, not financial gain. So why were details reportedly being sold online? What evidence is there that it was state-sponsored?
Verizon, which has agreed to buy Yahoo, said it had not been told until a couple of days ago - why not? And why is Marissa Mayer, a chief executive who has presided over bad deals and now the biggest breach in internet history, still in charge?Verizon, which has agreed to buy Yahoo, said it had not been told until a couple of days ago - why not? And why is Marissa Mayer, a chief executive who has presided over bad deals and now the biggest breach in internet history, still in charge?
Follow Dave on Twitter @DaveLeeBBCFollow Dave on Twitter @DaveLeeBBC
In July, Yahoo was sold to US telecoms giant Verizon for $4.8bn (£3.7bn).In July, Yahoo was sold to US telecoms giant Verizon for $4.8bn (£3.7bn).
Verizon told the BBC it had learned of the hack "within the last two days" and said it had "limited information".Verizon told the BBC it had learned of the hack "within the last two days" and said it had "limited information".
It added: "Until then, we are not in position to further comment."It added: "Until then, we are not in position to further comment."
Yahoo said in a statement: "Online intrusions and thefts by state-sponsored actors have become increasingly common across the technology industry."Yahoo said in a statement: "Online intrusions and thefts by state-sponsored actors have become increasingly common across the technology industry."
Reuters reported three unnamed US intelligence officials as saying they believed the attack was state-sponsored because it was similar to previous hacks linked to Russian intelligence agencies.Reuters reported three unnamed US intelligence officials as saying they believed the attack was state-sponsored because it was similar to previous hacks linked to Russian intelligence agencies.
Nikki Parker, vice-president at security company Covata, said: "Yahoo is likely to come under intense scrutiny from regulators, the media and public and rightly so. Corporations can't shy away from data breaches and they must hold their hands up and show that they are committed to resolving the problem."Nikki Parker, vice-president at security company Covata, said: "Yahoo is likely to come under intense scrutiny from regulators, the media and public and rightly so. Corporations can't shy away from data breaches and they must hold their hands up and show that they are committed to resolving the problem."
She added: "Let's hope the ink is dry on the contract with Verizon."She added: "Let's hope the ink is dry on the contract with Verizon."
Top 10 previous breaches Hack attacks
Source - haveibeenpwned.com Attacks on Yahoo have led to some users of the service being hit by hackers. Japan-based writer and journalist Ali Attas said he was devastated when he logged on to his email to find that everything he had sent and received for the last 20 years had disappeared.
"I've lost hundreds of contacts and a lot of very sensitive stuff," said Mr Attas, who lives near Yokohama. "It's devastating."
"My 20 year history has been wiped out. The damage is beyond repair."
In addition to all his personal and work contact details he said the vanished emails also included educational manuscripts he had submitted to publishing houses and a book idea which had been sent to a publisher in New York.
Fortunately he had back-up copies of some of his work.
He said he had set up a new account and emailed Yahoo to see if they can help him recover his work but had yet to receive a reply.
Questions are being asked about the length of time it took Yahoo to fully acknowledge the breach.Questions are being asked about the length of time it took Yahoo to fully acknowledge the breach.
"It is really worrying that a breach from 2014 can have gone undetected for so long," said Prof Alan Woodward from the University of Surrey."It is really worrying that a breach from 2014 can have gone undetected for so long," said Prof Alan Woodward from the University of Surrey.
"It is also surprising the public statement took so long to appear.""It is also surprising the public statement took so long to appear."
"I would have thought most companies had learned by now that early disclosure is better, even if you have to revise and update as you learn more.""I would have thought most companies had learned by now that early disclosure is better, even if you have to revise and update as you learn more."
The scale of the hack eclipses other recent, major tech breaches - such as MySpace (359 million), LinkedIn (164 million) and Adobe (152 million).The scale of the hack eclipses other recent, major tech breaches - such as MySpace (359 million), LinkedIn (164 million) and Adobe (152 million).
Have you had an email or other account hacked? What was your experience? Email haveyoursay@bbc.co.uk with your stories.Have you had an email or other account hacked? What was your experience? Email haveyoursay@bbc.co.uk with your stories.
On the BBC News Channel at 11:30am internet expert Grant Paling will be answering your questions on cyber security. Send them in using the form below.On the BBC News Channel at 11:30am internet expert Grant Paling will be answering your questions on cyber security. Send them in using the form below.
Please include a contact number if you are willing to speak to a BBC journalist. You can also contact us in the following ways:Please include a contact number if you are willing to speak to a BBC journalist. You can also contact us in the following ways:
·WhatsApp: +44 7525 900971·WhatsApp: +44 7525 900971
·Tweet: @BBC_HaveYourSay·Tweet: @BBC_HaveYourSay
·Send an SMS or MMS to 61124 or +44 7624 800 100·Send an SMS or MMS to 61124 or +44 7624 800 100
Or please use the form below:Or please use the form below: