Yahoo! Inc.carried out an investigation confirming that data linked with at least 500million user accounts was stolen from its network in late 2014 by what it deemsa "state-sponsored actor."
The stolen information may include names, e-mail addresses,telephone numbers, dates of birth, hashed passwords mostly with bcrypt, andeven encrypted or unencrypted security questions and answers. So far theinvestigation indicates that the stolen information did not include unprotectedpasswords, payment card data or bank account information, as the datapertaining to these was not stored in the system found to be affected.
The company is notifying potentially affected users andasking them to change their passwords. It has also taken steps to secure useraccounts, including the invalidation of unencrypted security questions andanswers.
As of yet, the investigation has not found any evidence thatsuggests that the state-sponsored actor is still in Yahoo's network. Thecompany is working with law enforcement regarding this matter, Yahoo said Sept.22.