Advertisement
Canada markets closed
  • S&P/TSX

    21,807.37
    +98.93 (+0.46%)
     
  • S&P 500

    4,967.23
    -43.89 (-0.88%)
     
  • DOW

    37,986.40
    +211.02 (+0.56%)
     
  • CAD/USD

    0.7275
    +0.0012 (+0.16%)
     
  • CRUDE OIL

    83.24
    +0.51 (+0.62%)
     
  • Bitcoin CAD

    87,421.28
    +2,908.00 (+3.44%)
     
  • CMC Crypto 200

    1,367.90
    +55.27 (+4.21%)
     
  • GOLD FUTURES

    2,406.70
    +8.70 (+0.36%)
     
  • RUSSELL 2000

    1,947.66
    +4.70 (+0.24%)
     
  • 10-Yr Bond

    4.6150
    -0.0320 (-0.69%)
     
  • NASDAQ

    15,282.01
    -319.49 (-2.05%)
     
  • VOLATILITY

    18.71
    +0.71 (+3.94%)
     
  • FTSE

    7,895.85
    +18.80 (+0.24%)
     
  • NIKKEI 225

    37,068.35
    -1,011.35 (-2.66%)
     
  • CAD/EUR

    0.6824
    +0.0003 (+0.04%)
     

How Yahoo's massive data breach stacks up with the worst of all time

Matej Moderc | Getty Images

At least 500 million user accounts have been stolen from Yahoo, the company confirmed on Thursday.

The data breach is the largest from a single site in history, according to a database of other hacking incidents. In August, hackers were discovered trying to sell 200 million Yahoo accounts, which would have been the second-largest single breach.

Recode reported on Thursday morning that the company was poised to confirm the compromised data, and that it was even worse than originally believed. The data, which was stolen in late 2014 by what the company called a "state-sponsored actor," may include names, emails, telephone numbers, dates of birth, hashed passwords, and security questions and answers, but not financial information, according to the company.

Russian hackers pulled off what seems like a much bigger haul of 1.2 billion users in 2014, but that data was stolen from hundreds of thousands of sites and combined into a single collection.

ADVERTISEMENT

The total numbers around cyberattacks are sometimes contested, but here's a rundown of the some of the biggest data breaches, according to a database maintained by Privacy Rights Clearinghouse:

After several months of research, cyber security firm Hold Security discovered that an unnamed Russian gang had amassed more than 4.5 billion credentials from websites across the web. About 1.2 billion of those were unique.

That amazing feat of online thievery was accomplished by buying a smaller set of credentials and using those to attack sites. They also used compromised accounts to search the web for other vulnerable sites, eventually robbing over 420,000 sites of all sizes.

Sometime before June 2013, the once-popular social networking site MySpace was attacked. It wasn't until May 2016 that the company (then owned by Time (TIME)) reported that 360 million accounts, with user names, passwords and emails, were for sale in an online hacker forum.

MySpace reacted by invalidating the passwords of accounts that were known to be included in the leak. Even so, users frequently use similar passwords on different sites, so stolen passwords can be used to gain access to other sites as well.

The hack was attributed to the Russian hacker "Peace," who also posted the original offer to sell the 200 million Yahoo accounts for $1,800 earlier this year.

"Peace" was also found trying to sell 167 million LinkedIn user accounts — 117 million of which had both emails and encrypted passwords — in 2016. The stolen data originated in a hack of the social network in 2012, during which 6.5 million passwords were reported as stolen.

Hundreds of millions of users not only had to change their LinkedIn (LNKD) passwords, but also had to worry about hackers using their information on other sites. For the full database for sale on the dark web marketplace, "Peace" was asking for only $2,200 in bitcoin.

Three months after its system was compromised using stolen login credentials from several employees, eBay (EBAY) announced that 145 million users would have to change their passwords. Financial information in the related PayPal money transfer service was not compromised, and the company said that no financial fraud was detected.

The hackers gained access to customer names, encrypted passwords, email addresses, physical addresses, phone number and dates of birth. Security experts said that criminals would be able to use that information for more old fashioned scams over the phone.

The 2008 attack on credit card processing company Heartland is the smallest and oldest on our list, but arguably caused more damage than larger hacks. Attackers spent months installing malware in a system that gave them access to credit card data.

Visa (NYSE:V) and MasterCard (MA) noticed suspicious activity and alerted the company. Heartland eventually paid about $140 million in fines and penalties for the data breach, and an American hacker was sentenced to 20 years in prison for his role in the attack.



More From CNBC

  • Top News and Analysis

  • Latest News Video

  • Personal Finance