Yahoo Breach Compromised 3 Billion People, Not 1 Billion

Latest Videos FromTom's Hardware
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • Lkaos
    What's 2.5 million in 145 million? 0.5% miss, stop making a big deal out of Equifax's number... Now, Yahoo's 3 billion over 1 billion is not only a 100% miss...That is the one you should be whorried about!
    Reply
  • USAFRet
    20238358 said:
    What's 2.5 million in 145 million? 0.5% miss, stop making a big deal out of Equifax's number... Now, Yahoo's 3 billion over 1 billion is not only a 100% miss...That is the one you should be whorried about!

    One of the main differences is...I have the choice not to use Yahoo's services. And haven't for many years.
    I don't have that choice with Equifax.
    Reply
  • spdragoo
    20238358 said:
    What's 2.5 million in 145 million? 0.5% miss, stop making a big deal out of Equifax's number... Now, Yahoo's 3 billion over 1 billion is not only a 100% miss...That is the one you should be whorried about!

    Technically it's 1.724%. But while it may seem statistically insignificant, it's very significant to those extra people.

    And there's the question of scale on this. Breaching Yahoo means they may have had access to your email account, but not every Yahoo account was necessarily tied into any kind of financial account (not to mention that, once you reset your password/changed your challenge questions & answers, you were no longer affected by the breach).

    In contrast, the Equifax breach gave them instant access to your personal information: name, SSN, address, (in some cases) bank account & loan account numbers, etc. -- all of the information needed for them to access your bank records & steal your identity...or worse, set up new credit card & other bank accounts technically in your name. And while the bank account numbers & bank access might be able to be changed, your SSN can't be changed. So for those affected by Equifax, that's a permanent piece of their personal information that is out there for a hacker to find.
    Reply
  • Lkaos
    You seriously believe that in roughly 3 billion users, a bigger number of those 145 million dont use their email accounts to send/receive/store any sort of financial records? Reality check needed...
    Reply
  • gaius_iulius
    20238807 said:
    You seriously believe that in roughly 3 billion users, a bigger number of those 145 million dont use their email accounts to send/receive/store any sort of financial records? Reality check needed...

    It still boils down to having a choice or not ... like USAFRet pointed out above.

    If somebody is dumb enough to ignore security advice easily accessible by simply browsing the Net for a few minutes, and actually uses something as insecure as Yahoo/Gmail/Live (or any of the Cloud Servers everybody thinks are so convenient) to store and/or transmit confidential or financial information, it's his own fault and deserves to be punished.

    Having your sensitive information compromised by the ignorance or negligence of a consumer credit reporting agency who collects and stores your financial data without your consent is a very different thing.
    The responsible individual(s) at Equifax should be indicted and sentenced to lenghty terms in jail.
    Reply
  • Lkaos
    The point is missing 2.5 million in a 145 million estimate ia not a big deal...
    An estimate is just that, an estimate...it's not an exact number...If they had said the number was 150 million and the affected really were 143 million they wouldnt be posting this news again...
    Reply
  • USAFRet
    20239387 said:
    The point is missing 2.5 million in a 145 million estimate ia not a big deal...
    An estimate is just that, an estimate...it's not an exact number...If they had said the number was 150 million and the affected really were 143 million they wouldnt be posting this news again...

    The point is that both of those breaches are bad.
    Reply
  • vern72
    I doubt they didn't know that they breach was that big. They just wanted a higher selling price when they sold the company.
    Reply
  • spikey in tn
    We have already had to change our passwords because of those monkeys. Now, the same * is starting again. When will they ever learn?
    Reply
  • thundervore
    Wow, so Yahoo revealed FOUR year later that the actual number is 3 times greater? Think of all those peoples information that hackers were accessing for 4 long years without the owner knowing.

    Thanks Yahoo. Just when I thought when they turned down the deal to buy google was bad, then comes this lol.
    Reply