• Photo
A Yahoo sign stands outside the company's offices in Santa Clara, Calif.

A Yahoo sign stands outside the company's offices in Santa Clara, Calif., Monday, May 20, 2012. (AP Photo/Paul Sakuma)

  • Consumer Tech
Car uses tweets and social media to run
Car uses tweets and social media to run

The car is an old-school Volkswagen Karmann Gia, but there's …

Viral videos stoke celebrities' images

NEW YORK (AP) — Mila Kunis' stardom went up a notch last week, and you would think it's …

Google pays $7M fine to settle…

SAN FRANCISCO (AP) — Google will pay a $7 million fine to settle a multistate …

Europe gets 1st fix from its…

BERLIN (AP) — The European Space Agency says it has received the first location fix from …

Conn. to receive $500,000 from…

HARTFORD, Conn. (AP) — Connecticut will receive more than $500,000 from Google Inc. as …

Advertisement

Yahoo investigating reported mass password breach

Report: Hacker group D33D Co. claim responsibility

Updated: Thursday, 12 Jul 2012, 9:08 AM EDT
Published : Thursday, 12 Jul 2012, 8:06 AM EDT

LONDON (AP) — Yahoo Inc. said Thursday it is investigating reports of a security breach that may have exposed nearly half a million users' email addresses and passwords.

The company said it was looking into "claims of a compromise of Yahoo! user IDs" but did not disclose the size of the reported breach or how it may have happened. Yahoo's Head of U.K. Consumer PR Caroline MacLeod-Smith said that she couldn't immediately provide any more detail on the breach "as we are still investigating it."

Technology news websites including CNET, Ars Technica, and Mashable cited hackers calling themselves the D33D Company as claiming responsibility for the attack, adding that data posted to the group's website carried more than 453,000 login credentials from an unidentified Yahoo subdomain.

The little-known group was quoted as saying that they had stolen the passwords using an SQL injection — the name given to a commonly-used attack in which hackers use rogue commands to extract data from vulnerable websites.

"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call," the group was quoted as saying.

A Ukraine-registered website associated with D33D Company appeared to be unreachable Thursday; an email address and a phone number attributed to the site's registrant appeared to be invalid.

  • Comments

Comments WLFI.com is migrating to a more stable commenting system called DISQUS. This system is used by CNN, TIME, FOX News, numerous blogging sites and has over 75 Million registered users. Unfortunately we can't migrate our current user accounts to this new system.

To sign up for a DISQUS account, click the DISQUS button just below and to the right and then click Login.

DISQUS lets you login with several different options, including Facebook, Google, Twitter, Yahoo or OpenID. We expect it to allow more conversation and better moderation. If you have any questions, please feel free to comment below.

 

blog comments powered by Disqus

Advertisement
Advertisement