Security firm InfoArmor says hackers-for-hire, not state-sponsored actors, breached Yahoo, and have sold the entire database three times, once for $300K+
Elite hackers-for-hire were actually behind the breach, according to InfoArmor — Common criminals, not state-sponsored hackers …
Context & Ripple Effects
Six days after Yahoo blamed the theft of data from 500M+ accounts on a state-sponsored actor, security firm InfoArmor is offering a rival attribution: elite hackers-for-hire did it, then sold the entire database three times, once for over $300,000. The claim gives a commercial backstory to what had been framed as espionage.
It also fits an existing pattern: in August, a hacker known as Peace was already shopping a dump of alleged credentials for 200M+ Yahoo accounts for just 3 BTC. If InfoArmor is right, that listing was one slice of a much larger asset changing hands on the criminal market.
First-order effects
- Yahoo's official narrative is directly challenged: its state-sponsored attribution now competes with a private firm's criminal-for-hire account, and the company must reconcile the two or defend its own.
- Three separate buyers hold (or held) the full user database — emails, hashed passwords, and security questions per Yahoo's own confirmation — multiplying exposure well beyond the original intrusion.
Second-order effects
- The FBI's finding that the breach likely began with a spear phishing email to a semi-privileged employee fits either attribution, so the entry-vector evidence won't settle the dispute — pushing the argument toward motive and buyer identity instead.
- If the database was sold as a commodity rather than used for targeted espionage, Yahoo's later disclosures — including the 1B+ account theft from 2013 and the forged-cookie attack it tied to the same state-sponsored attackers — face pressure to be re-examined under a criminal-market lens.
Third-order effects
- Breach attribution is becoming contested territory between governments and private security vendors, with each side's framing carrying different consequences for victim companies' liability, disclosure obligations, and diplomatic fallout.
- Mega-breaches functioning as sellable inventory — resold repeatedly at six-figure prices — points toward a structural shift where stolen databases trade like assets, making the original intrusion only the first transaction in a longer monetization chain.
The trend: Major breach attributions are increasingly disputed between state-actor narratives and criminal-marketplace economics, with private security firms and governments offering competing accounts of the same intrusion.