Tag: data breach

Update on Yahoo Breach

In November 2016, Yahoo realised it had suffered a data breach back in 2013. Yahoo released information on what had happened and informed everyone who may have been affected by this.

See blog post https://fightback.ninja/the-yahoo-data-breach-reported-december-2016/ for more information.

Yahoo has now released more information concerning how this happened.


Yahoo say they called in outside forensic experts to examine what happened and there has been the creation of forged cookies that could allow an intruder to access users’ accounts without a password. Based on the ongoing investigation, the outside forensic experts have identified user accounts for which they believe forged cookies were taken or used in 2015 or 2016.

The company is notifying the affected account holders, and has invalidated the forged cookies. They have connected some of this activity to the same state-sponsored actor believed to be responsible for the data theft we disclosed on September 22, 2016.

If you have not been contacted by Yahoo specifically about this, then your account will not have been affected.

However, if you have a Yahoo account then you should have changed your password and security questions and answers recently. If you haven’t done this then you should ASAP and also any other accounts that use the same login and password.


It is wise to review all of your accounts for suspicious activity and be cautious of any unsolicited communications that ask for your personal information or refer you to a web page asking for personal information.

Yahoo are doing everything they can to protect their customers data.

For further information go to https://help.yahoo.com/kb/account/SLN27925.html


Do enter your email address and click on the subscribe button on top right to keep up to date with new posts.

The Yahoo Data Breach Reported December 2016

If you are a registered user of Yahoo then you will have received an email from Yahoo explaining what happened in the data breach that has been reported on TV and in newspapers this month.  Someone collected a huge amount of information from Yahoo without their knowledge in August 2013 and it was only in December 2016 that Yahoo found out it’s security had been breached.

Yahoo believe the data copied contains name and email address, telephone numbers, date of birth and in some cases hashed passwords and security questions and answers. But does not include any financial information or credit card numbers etc.

Yahoo only found out about this when  asked by Law Enforcement to examine some data that turned out to be from Yahoo and their investigation proved what had happened three years previously.

  1. As a Yahoo User What Must I Do?

If you have not changed your Yahoo password recently then do so quickly and make sure to set a safe password [https://fightback.ninja/how-to-keep-your-passwords-safe/]. You should also change your security questions.

Check your accounts for any suspicious activities and remember that scammers sometimes only take small amounts for a period of months, hoping to be ignored.

  1. What About Other Online Logins and Passwords?

If you have other accounts that use the same login and password as Yahoo then you should change them quickly. Once scammers have your login and password they will check other websites to see if you’ve used the same information.

Ideally you should use different logins and passwords for each website you’re registered with. However, that may be impractical for people with lots of such logins but you should at least use a set of logins and passwords and not the same one for every web site.

Note: If you receive an email or call from someone claiming to work for Yahoo – be suspicious and do not divulge any confidential information even if they seem to have your information already.

Go to http://yahoo.com/security-update for further information from Yahoo.

Do Share this post on social media – click on the post title then scroll down to the social media share buttons.

Major Organisations Hacked in the UK in 2016


There have been a lot of company data breaches in 2016 in the UK but the three biggest known such breaches are

  • Three mobile phone company
  • Tesco bank
  • Sage business software company

Three Mobile

Three, one of Britain’s largest mobile operators revealed it’s had a major data breach that could put millions of its customers at risk. Hackers accessed Three’s customer upgrade database via using an employee login. They didn’t get access to any financial data but did access  names, phone numbers, addresses and dates of birth of its customers.

Tesco Bank

Tesco Bank which is part of Tesco supermarkets, had to freeze the online accounts of online customers as 20,000 people had money stolen from their accounts.

You can imagine what the customers thought of suddenly finding their bank cards were rejected. Everywhere and then for some that money had disappeared from their accounts.

Tesco Bank, which has over seven million customer accounts, has said it will cover any financial costs of the breach.


Sage is a business software company and is part of the FTSE-100 index.

Sage said their data breach could have compromised the personal data of 280 businesses that use Sage.

Attitudes to Data Breaches

A recent survey into attitudes towards organisations that have experienced data breaches shows that 84 percent of respondents would reduce or stop using an organisation’s products or services following breaches, and only 16 percent of respondents would continue to use an organisation’s products or services as usual.

Respondents were asked: “If you found out an organisation whose products or services you use had multiple data breaches, which of the following best describes how you would react?”

16 percent – I would continue to use their products or services as usual

27 percent – I would limit my usage of their products or services

37 percent – I would only use their products or services if I had no alternatives

20 percent – I would stop using their products or services completely

Businesses (especially those in the public eye such as FTSE-100 companies) need to understand that if their online security is not up to standard and they are hacked – that has a chilling effect on their customers and it will be hard to repair their reputation.

Do enter your email address and click on the subscribe button on top right to keep up to date with new posts.