On the same day as a report that says Verizon is renegotiating its offer to buy Yahoo at a $250 million discount, the internet company is—for the third time in less than six months—warning users that there's potential their email accounts may have been hacked.
Yahoo confirmed today that it was notifying users that their accounts may have been accessed illicitly between 2015 and 2016 but declined to say how many people were affected. However, sources familiar with the matter tell Consumerist that notifications have gone out to a reasonably final list of users and the security investigations are in their final stages.
"Based on the ongoing investigation, we believe a forged cookie may have been used in 2015 or 2016 to access your account," the company wrote in an email to users today.
Related Stories From Consumer Reports
More From Consumer Reports
- Want to Dump Your Yahoo Email? Here's How
- Yahoo's Biggest Data Hack: What You Should Do Now
- Stolen Yahoo Passwords Were Encrypted, but That Doesn't Mean Users Are Safe
- Consumer Reports' Guide to Internet Safety
Yahoo first mentioned those "forged cookies" by Yahoo in December, when it announced the hack of one billion accounts: The company believes some some bad actors got access to proprietary code in order to forge cookies that let them log into users' accounts without even having a password, stolen or otherwise.
The forged cookie incident, the company said in December, is probably related to the breach of 500 million accounts it reported in September. That would make this the third event for Yahoo, but it's likely the same bad actor behind these two, at least.
"As we have previously disclosed, our outside forensic experts have been investigating the creation of forged cookies that could have enabled an intruder to access our users' accounts without a password," a Yahoo spokesperson said in a statement. "The investigation has identified user accounts for which we believe forged cookies were taken or used. Yahoo is in the process of notifying all potentially affected account holders. Yahoo has invalidated the forged cookies so they cannot be used again."
Copyright © 2005-2017 Consumers Union of U.S., Inc. No reproduction, in whole or in part, without written permission. Consumer Reports has no relationship with any advertisers on this site.