{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-yahoo-network-breached-via-spear-phishing-email-500-million-accounts-sto"},"incident":{"slug":"2014-yahoo-network-breached-via-spear-phishing-email-500-million-accounts-sto","title":"Yahoo network breached via spear-phishing email, 500 million accounts stolen","date":"2014","date_precision":"year","year":2014,"victim_org":"Yahoo! Inc.","sector":"Technology","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":500000000,"threat_actor":"Russian FSB officers Dmitry Dokuchaev and Igor Sushchin with criminal hackers Alexsey Belan and Karim Baratov (per 2017 DOJ indictment)","summary":"In 2014 attackers obtained access to Yahoo's internal User Database and Account Management Tool and stole data associated with roughly 500 million accounts. The US Department of Justice indicted two FSB officers and two hackers in March 2017. Reporting on the indictment stated the intrusion began with a spear-phishing email sent to a Yahoo employee in early 2014, and that only one recipient needed to click for the attackers to gain a foothold.","how_it_worked":"The operation opened with a spear-phishing email sent to Yahoo staff in early 2014. The message carried custom content tailored to the recipient so it read as ordinary internal or business correspondence, and required only a single click on a malicious link to succeed. Once a foothold existed, one of the criminal hackers moved laterally to Yahoo's User Database and its Account Management Tool, then minted forged authentication cookies that let the group open targeted mailboxes without any password. The intelligence-service sponsors used that capability to read the mail of journalists, officials and company executives of interest.","lessons":"Phishing-resistant authentication on administrative tooling, plus segmentation so a single employee foothold cannot reach the master user database, would have contained the initial click.","confidence":"Reported","sources":[{"title":"Inside the Russian hack of Yahoo: How they did it","url":"https://www.csoonline.com/article/560623/inside-the-russian-hack-of-yahoo-how-they-did-it.html","publisher":"CSO Online"},{"title":"Four Men Charged With Hacking 500M Yahoo Accounts","url":"https://krebsonsecurity.com/2017/03/four-men-charged-with-hacking-500m-yahoo-accounts/","publisher":"Krebs on Security"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2014-yahoo-network-breached-via-spear-phishing-email-500-million-accounts-sto"}}