29 Sep 2016

Yahoo's exfiltration of MD5 credentials

  • Login ID
  • Country Code
  • Date of Birth
  • Recovery email address & zipcode
  • MD5 hash based password
  • Mobile phone number
  • Yahoo initially investigated the possibility of the breach in July after discovering hackers Tessa88 and ‘Peace of Mind’ were trying to sell segments of legitimate mixed with bogus data dumps of Yahoo credentials.   At the same time period of the investigation Yahoo was selling its internet business and some real estate for $4.8B to Verizon Communications.  On September 9th in their securities filing, Yahoo claimed it was not aware of any loss, theft, unauthorized access, or security breach of user data. [caption id="attachment_7253" align="alignright" width="474"]example of Yahoo hash based credentials example of Yahoo hash based credentials[/caption]]]>