Cyberattacks are relatively common these days, but those who organize them are no longer simple independent actors seeking economic advantage. According to a recent announcement by Yahoo!, at least 500 million accounts were compromised in late 2014, through an attack sponsored by a government or federal agency. The obvious recommendation from Yahoo! to its users is to change passwords, but the question is: Why did they take so long?.
The Breach
Do you have a Yahoo! account? Have you changed your password or security questions in the last two years? If you answered yes to the first and no to the second, then you have homework. The battered online platform that was acquired by Verizon last July just acknowledged a cybersecurity crisis that extends to late 2014. It seems incredible that the company waited until September 2016 to acknowledge the leak, especially given the number of affected users. Yahoo!'s own statement speaks of "at least 500 million accounts", but there is a very important detail: the attacker was allegedly sponsored by a state or government agency.
What Data Was Stolen?
Who attacked Yahoo!? We will probably never know, but what has been confirmed is the type of information stolen: names, email addresses, phone numbers, birth dates, hashed passwords, and in some cases, security questions and answers, both encrypted and unencrypted. The internal investigation (which is still ongoing) did not reveal the leak of passwords, banking data, or credit card numbers, since that data is not stored on the attacked system. Yahoo! has already begun the process of contacting those users it considers at higher risk to modify their account security parameters, and all exposed security question-answers have been invalidated.
What Should You Do?
Personally, I recommend not waiting for Yahoo!'s formal contact. To change your password and edit security questions, the company offers this link, but you will need to log in with your current credentials before making any changes. As a final point, Yahoo! has said that Tumblr accounts were not affected. Change your password, don't waste time.