Showing posts with label Yahoo email. Show all posts
Showing posts with label Yahoo email. Show all posts

Friday, December 16, 2016

Important Yahoo warning - close down any Yahoo accounts you have NOW!

Yahoo just announced another security breach where a whopping billion accounts were hacked. This is the second time in a matter of months that Yahoo has announced a security breach - what an epic fail! This latest hack is being hailed the largest in history, according to CNBC (source).

The forensic investigation is still going on, but it is highly likely that the bad guys initially got in through a spear phishing attack with a spoofed 'From' address. These types of attacks are hard to spot and employees tend to fall for them. 

At this point, Yahoo has fallen down on security in so many ways that we are now advising all our clients who have an active Yahoo email account, either direct with Yahoo of via a partner like AT&T, get rid of it. And in case you have employees who check their Yahoo account on lunch breaks... it's time to put Yahoo on the block list of your firewall and all filtering software & devices.

Here's some hints and tips for Yahoo account owners....
  1. Before you delete the account, get rid of all the folders and only then delete the account and open a free gmail account instead.
  2. Check if you have used your Yahoo password in other sites, and change the password and security questions for those accounts. And remember, never reuse your email password (or any other password tied to an account that holds sensitive data about you) at any other site.
  3. If you used a mobile phone number in association with your Yahoo account, and you still use that mobile phone number, then SMS phishing (a.k.a. Smishing) is now a distinct possibility, so be very wary of this.

Tuesday, September 27, 2016

Yahoo hack: It's not just Verizon; AT&T customers should be worried too.

The massive hack that Yahoo disclosed last week is a headache for Verizon, the telecom giant set to take ownership of the company early next year.

Rival AT&T should be nervous too...

That's because many AT&T customers get the option to use a Yahoo Mail account to manage services like home broadband, wireless and pay-television services.

It's the outgrowth of a partnership from 15 years ago between Yahoo and AT&T (then called SBC Communications), bringing AT&T broadband customers to Yahoo's search engine and media services, including Yahoo Mail. At the time, critics hailed the deal as a landmark partnership that would better combat the growing power of AOL and Microsoft's MSN portal.

Today, AOL is part of Verizon, Microsoft's MSN is no more and AT&T likely isn't feeling so great about the deal.

Yahoo said Thursday that the hack compromised at least half a billion accounts containing user names, email addresses and passwords. That makes it the biggest attack ever. US Senator Mark Warner has asked the Securities and Exchange Commission to investigate the matter.                                    
The hack puts AT&T in an uncomfortable position. The company is still waiting for data from Yahoo on the specific customers who may have been affected, according to a person familiar with their dealings.

"We began investigating immediately and requested information from Yahoo necessary to determine which email accounts may have been compromised," the company said in a statement. "In the meantime, we are in the process of notifying potentially affected customers."

Chances are, a significant number of AT&T customers are affected.

AT&T was in the middle of breaking up with Yahoo before the attack, having announced in May that it would instead tap Synacor to handle its internet and mobile portal business.
The loss of the deal, worth an estimated $100 million a year, came at a time when chatter had heated up over potential suitors for Yahoo. AT&T was among the rumored bidders, but Verizon snagged the internet pioneer with a $4.8 billion offer.

For now, AT&T is offering little advice to its customers beyond the standard line: regularly change your passwords.

That, along with these other tips, is advice everyone should heed.

Monday, September 26, 2016

This is what you should do if your Yahoo account was hacked.

The company said on Thursday at least 500 million user accounts were affected by a massive data breach. The hack happened in 2014, when "state-sponsored actor" stole account information, including names, emails, passwords, telephone numbers and answers to some security questions.

So what should you do if you have a Yahoo account?

First and foremost, you'll want to change your password immediately. All Yahoo account holders should also change their security questions and answers.

If your account is one Yahoo suspects was compromised, you'll be prompted to enter a new password as soon as you log on. If you used the same password on other accounts, change those, too.

Here are other steps to take to secure your online accounts.

Change passwords often
Yahoo is asking anyone who hasn't changed their password since 2014 to update it. This is good advice for everyone: Passwords should be changed often. You won't always get a timely notice from a company that an account was compromised -- and sometimes it might not even know about a hack until much later. In this case, it took two years for the company to confirm the breach.

Never use the same password twice
If hackers get the password for one of your online accounts, they can try to use it to access your other accounts that take the same credentials.

Pick better passwords
Consider using a phrase instead of single words that are more easily guessed. Don't go for common phrases like cliches: Pick a combination of words that don't go together -- i.e. rather than "herecomesthesun," go for something like "waterfiresnowsunshine".

Avoid using common passwords like 1-2-3-4-5-6 or p-a-s-s-w-o-r-d, and include a mixture of numbers, letters and characters.

Use a password manager
Since strong unique passwords are a huge pain to memorize, try a password manager like 1Password or LastPass. These platforms generate and store passwords and security answers for every account you have, so you only have to remember a single master password.

Update those security questions
If you forget a password, using security questions is an easy way to gain access back into your own account -- its not like you'll ever forget your mom's maiden name. But some Yahoo security answers and questions were a part of the breach. The company has already disabled any unencrypted security answers on its accounts.

If you frequently use the same security questions and answers for other online accounts, you'll want to change those, as well. Attackers could use the information taken from Yahoo to obtain access to other online accounts that contain even more sensitive information.

Avoid choosing the obvious questions and don't provide answers that are easy to find online through Google searches or social media sites.

Be alert
The company is urging users to look through their Yahoo accounts (email, calendar, groups, etc.) for any signs of suspicious activity. Although it doesn't say what to look for, start by checking outgoing emails.

Be extra careful about clicking on links or opening downloads from unknown email addresses. If anyone emails asking for your password, it's a red flag -- even if it looks like it's coming from a legitimate place like Yahoo or a bank. Never share any account information or passwords over email.

Turn on two-factor authentication
On its own, a password isn't a strong line of defense. Adding a second type of authentication, like a one-time code sent over text message or generated by an app, can greatly secure your online accounts.

Yahoo is recommending people turn on its two-factor authentication tool: Yahoo Account Key. It even eliminates the need to memorize a Yahoo password.

If you use the Yahoo Android or iOS app, log in to your account, go to your profile and select Account Key. You can also set it up in a web browser. Each time you try to access your account, Yahoo will send a confirmation to your phone.

While it's certainly an extra step, make it a part of your daily routine. Next time there's a story about a massive data breach, you'll be glad you did.