Yahoo on Tuesday said that all 3 billion of its accounts were hacked in a 2013 data theft, tripling its earlier estimate of the size of the largest breach in history, which already had spawned a nationwide lawsuit.
Yahoo said last December that data from more than 1 billion user accounts was compromised in 2013, the largest of a series of thefts that forced Yahoo to cut the price of its assets in a sale to Verizon Communications, its current owner.
Yahoo on Tuesday said "recently obtained new intelligence" showed all user accounts had been affected. However, the company said the investigation indicated that the stolen information did not include passwords in clear text, payment card data, or bank account information.
Verizon in February lowered its original offer by US$350 million for Yahoo assets in the wake of two massive cyber attacks at the internet company.
In August, U.S. Judge Lucy Koh in San Jose, California, ruled Yahoo must face nationwide litigation brought on behalf of well over 1 billion users who said their personal information was compromised in the three breaches.
"Judge Koh had asked us to provide additional facts to support what we knew about the 2013 breach. I think we have those facts now," said John Yanchunis, a lawyer representing some of the Yahoo users.
The closing of the Verizon deal, which was first announced in July, had been delayed as the companies assessed the fallout from two data breaches that Yahoo disclosed last year. The company paid US$4.48 billion for Yahoo's core business.
A Yahoo official emphasized Tuesday that the 3 billion figure included many accounts that were opened but that were never, or only briefly, used.
The company said it was sending email notifications to additional affected user accounts.
The new revelation follows months of scrutiny by Yahoo, Verizon, cybersecurity firms and law enforcement that failed to identify the full scope of the 2013 hack.
The investigation underscores how difficult it was for companies to get ahead of hackers, even when they know their networks had been compromised, said David Kennedy, chief executive of cybersecurity firm TrustedSEC LLC.
Companies often do not have systems in place to gather up and store all the network activity that investigators could use to follow the hackers' tracks.
“This is a real wake up call,” Kennedy said. “In most guesses, it is just guessing what they had access to."
(Reporting by Munsif Vengattil, Jim Finkle, Jim Christie, Jon Stempel, and David Shepardson; writing by Stephen Nellis in San Francisco; Editing by Anil D'Silva and Andrew Hay)
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.