

"The fact is attackers are having field days and the problem is only going to get worse," Johnson said. Another scenario is that accounts thought not to be compromised may have appeared for sale or are being used by criminals. Johnson said it's possible that during due diligence of the company's sale, investigators found new information. Related: Former Equifax CEO testifies before Congress In the case of the massive breach at credit monitoring firm Equifax, for instance, the company initially said the hacking affected 100,000 Canadians, but later revised that number to just 8,000. In any breach it's safe to assume the number of affected accounts will be adjusted, he said. He also said that internal investigations might miss something, and outside experts focused on digital forensics will find more than an internal team.īen Johnson, chief technology officer at Obsidian Security, says Yahoo may never know exactly what was accessed.

"Initially, the investigation establishes a set of compromised systems and data that encompasses a set of users, then later something is discovered that expands the compromised systems access." "This often happens with breaches, on a much smaller scale," said Wesley McGrew, a security expert at Horne Cyber.
3d katie account hack password#
Following the hacking revelations last year, Yahoo required password changes and invalidated unencrypted security questions to protect user information.Īccording to experts, it's not uncommon for forensic investigations to expose a greater number of victims than initial estimates.

Yahoo will send emails to the additional affected accounts. Verizon would not provide any information about who the outside forensics experts are. "The company recently obtained new intelligence and now believes, following an investigation with the assistance of outside forensic experts, that all Yahoo user accounts were affected by the August 2013 theft," Verizon said in a statement. Verizon revised the number of breached accounts to three billion after receiving new information.
