Yahoo reveals another hack where an “unauthorized third party” in Aug. 2013 stole data from 1B+ accounts including names, emails, telephone numbers, birthdates
Yahoo has disclosed that — in addition to its September hacking incident — another “unauthorized third-party” …
Context & Ripple Effects
Two months after Yahoo confirmed a 500M-account theft from 2014 attributed to a state-sponsored actor, it discloses a second, older intrusion: an unauthorized third party pulled data on more than 1 billion accounts in August 2013. The new disclosure is twice the size of the first and predates it by a year.
It also lands mid-investigation: Yahoo had already admitted some employees knew of the 2014 hack and launched a probe into who knew what internally. Meanwhile attribution is contested — InfoArmor has argued hackers-for-hire, not a state, breached Yahoo and sold the full database three times, once for $300K+.
First-order effects
- Over a billion account holders learn their names, emails, phone numbers, and birthdates were taken three years ago, forcing Yahoo into another wave of notifications and credential resets stacked on top of the September disclosure.
- The internal-knowledge probe now covers a bigger question set: if employees knew of the 2014 breach, the existence of a larger 2013 one sharpens scrutiny of why neither surfaced until after the fact.
Second-order effects
- If InfoArmor is right that the database has already been sold three times, the stolen identities are circulating commercially now — feeding phishing and account-recovery attacks against any service where users tied a Yahoo address to their identity.
- Dueling attributions — Yahoo's state-sponsored claim versus InfoArmor's hackers-for-hire narrative — change how enterprise partners and advertisers price the risk of Yahoo's mail and account ecosystem.
Third-order effects
- The pattern of breaches disclosed years late and then repeatedly upsized — Verizon later put the same incident at all 3 billion users — pushes regulators toward harder breach-notification deadlines and makes disclosure history a standard diligence item in tech acquisitions.
- Serial mega-disclosures erode trust in legacy free-email platforms as identity anchors, nudging users toward providers that compete on security posture rather than incumbency.
The trend: Mega-breaches at legacy consumer platforms now surface in installments, with each disclosure older and larger than the last as forensics and litigation widen the scope.