What happened
In 2014 attackers obtained access to Yahoo's internal User Database and Account Management Tool and stole data associated with roughly 500 million accounts. The US Department of Justice indicted two FSB officers and two hackers in March 2017. Reporting on the indictment stated the intrusion began with a spear-phishing email sent to a Yahoo employee in early 2014, and that only one recipient needed to click for the attackers to gain a foothold.
How the deception worked
The operation opened with a spear-phishing email sent to Yahoo staff in early 2014. The message carried custom content tailored to the recipient so it read as ordinary internal or business correspondence, and required only a single click on a malicious link to succeed. Once a foothold existed, one of the criminal hackers moved laterally to Yahoo's User Database and its Account Management Tool, then minted forged authentication cookies that let the group open targeted mailboxes without any password. The intelligence-service sponsors used that capability to read the mail of journalists, officials and company executives of interest.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant authentication on administrative tooling, plus segmentation so a single employee foothold cannot reach the master user database, would have contained the initial click.
Sources (2)
- Inside the Russian hack of Yahoo: How they did itCSO Online·csoonline.comOpen ↗
- Four Men Charged With Hacking 500M Yahoo AccountsKrebs on Security·krebsonsecurity.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.