This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Hackers claim to have stolen 450,000 Yahoo logins

by Alastair Stevenson

12 Jul 2012

View Comments

  • Tweet this
yahooearningslogo

Hackers claim to have breached Yahoo's security, posting the alleged login details of over 450,000 users.

The attack reportedly targeted the company's Yahoo Voices platform with a union-based SQL injection technique - a form of attack that tries to trick a SQL database to run a string containing malicious code.

The hackers posted over 453,000 alleged login credentials to the D33D Company website as proof of the breach, claiming the attack was intended to be a wake up call for Yahoo.

"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat," the group said.

"There have been many security holes exploited in webservers belonging to Yahoo that have caused far greater damage than our disclosure. Please do not take them lightly. The subdomain and vulnerable parameters have not been posted to avoid further damage."

Yahoo told V3 that it was investigating the hackers' post and encouraged users to change passwords regularly.

"At Yahoo we take security very seriously and invest heavily in protective measures to ensure the security of our users and their data across all our products. We are currently investigating the claims of a compromise of Yahoo user IDs," said a Yahoo spokesman.

"We encourage users to change their passwords on a regular basis and also familiarise themselves with our online safety tips at security.yahoo.com."

Prior to the hackers post, question and answer site Formspring confirmed it had disabled its users passwords after around 420,000 hashed passwords claiming to belong to the site were posted to a security forum.

The breaches come after several high-profile password thefts in June with LinkedIn and Last.fm both affected.

Do you agree

blog comments powered by Disqus

Poll

Microsoft v Google

Which productivity tools do you use for work?

38%

6%

2%

2%

21%

31%

Popular Threads

Powered by Disqus
Sony Xperia Z vs Apple iPhone 5

Sony Xperia Z vs Apple iPhone 5 head to head video review

V3 pits Sony's rugged flagship against Apple's premier handset

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

Business Analyst - Financial Services

Business Analyst - Financial Services - required for...

QlikView Consultant

QlikView Consultant / QlikView Developer required for...

Business Intelligence Developer

Business Intelligence Developer (SSIS SSAS SSRS) required...

SharePoint Developer

SharePoint Developer (Senior) required for a MS Gold...

To send to more than one email address, simply separate each address with a comma.