Yahoo attack places spotlight on identity management
The attack on Yahoo that started with the theft of user credentials from a third-party database highlights the risk of sharing usernames and passwords across multiple websites.
Yahoo reported Thursday that attackers using computer software used the stolen credentials to log into Yahoo Mail accounts and search for names and email addresses on sent emails. Upon discovering the attack, Yahoo shutdown access to the affected accounts, alerted users and asked that they reset their passwords.
Yahoo, which did not disclose how many webmail accounts were affected, said it had no evidence that the usernames and passwords came from its own systems. "Based on our current findings, the list of usernames and passwords that were used to execute the attack was likely collected from a third-party database compromise," Yahoo said.