Yahoo issues new warnings of potential malicious activity on accounts between 2015 and 2016 related to forged cookies, won't disclose number of users affected
Context & Ripple Effects
This warning lands in the middle of Yahoo's rolling breach disclosures: after confirming the 500M+ account theft by a state-sponsored actor in September 2016 and the separate 1B+ account intrusion from August 2013, the company is now flagging a third vector — forged cookies that let attackers access accounts without passwords between 2015 and 2016 — while again withholding scale.
The refusal to disclose numbers extends a pattern already under scrutiny: Yahoo had earlier admitted some employees knew of the 2014 hack at the time and opened an internal investigation into who knew what. Two weeks later, Yahoo would quantify this cookie campaign at 32M affected accounts tied to the same attackers.
First-order effects
- Users active on Yahoo accounts during 2015-2016 face new security warnings and forced credential resets, since forged cookies bypass passwords entirely.
- Yahoo's pending acquisition by Verizon faces fresh diligence risk, as each undisclosed-scope disclosure erodes the price and terms negotiated for the deal.
Second-order effects
- Verizon gains leverage to renegotiate or walk from the acquisition, and its later finding that the 2013 incident actually hit all 3B Yahoo users shows how repeatedly the scope expanded after each initial estimate.
- Rival email and portal providers can market against Yahoo's disclosure cadence, pushing passwordless and session-security features up their own roadmaps.
Third-order effects
- If acquirers systematically reprice targets over withheld breach scope, M&A diligence will treat undisclosed incident counts as a standard contingency rather than an exception.
- State-sponsored attribution becoming routine in consumer-breach disclosures points toward regulators treating nation-state attacks on consumer platforms as a distinct disclosure category with harder reporting requirements.
The trend: Yahoo's serial breach disclosures — each initially understated, then revised upward — are turning acquisition-time security diligence into the decisive variable in large internet M&A.