{"id":3340,"date":"2016-10-20T03:58:19","date_gmt":"2016-10-20T03:58:19","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=3340"},"modified":"2019-03-08T19:52:15","modified_gmt":"2019-03-09T00:52:15","slug":"the-record-breaking-yahoo-cyber-security-breach-a-reasonable-disclosure-or-a-calculated-cover-up","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2016\/10\/20\/the-record-breaking-yahoo-cyber-security-breach-a-reasonable-disclosure-or-a-calculated-cover-up\/","title":{"rendered":"The Record-Breaking Yahoo Cyber-Security Breach: A Reasonable Disclosure or A Calculated Cover-up?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-3341\" src=\"http:\/\/jolt.richmond.edu\/files\/2017\/03\/cyber-security-346x242.jpg\" alt=\"cyber-security\" width=\"346\" height=\"242\" \/><\/p>\n<p>By: Kaley Duncan,<\/p>\n<p>Cyber-security is a growing concern worldwide.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> Continued increase in information sharing via the internet has left this information susceptible to hacker exploitation.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> The motive for many cyber-attacks is to sell information gained to sites that use that information for identity theft. <a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a> If you are like me, your passwords are not only less than creative, but are also likely used for multiple accounts. As such, if your security information has been compromised, the effects can be far-reaching; it could affect not only information from your recent email correspondences, but possibly more important information, such as your bank account number and social security number.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a> Big companies, and even the government, have been looking for ways to combat these hacks.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a> So far in 2016, nineteen companies including Target, Walmart, Snapchat, and the IRS have been targeted by hacking schemes. <a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a> Recently, another prominent name has been added to the list.<\/p>\n<p>On Thursday, September 22<sup>nd<\/sup>, the email platform Yahoo confirmed that 500 million of its user accounts had been hacked.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a> This is the largest security breach on record.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a> Stolen information included emails, passwords, birth dates, telephone numbers, and, in some cases, even security questions.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a> To make matters worse, Yahoo informed the public that these hacks started in 2012 and were just recently discovered by the company\u2019s security team.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a><\/p>\n<p>Multiple lawsuits have been filed including a class action alleging gross negligence.<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a> The suit, filed by New York resident Ronald Shwartz, contends Yahoo\u2019s security team knew of the breach long before they disclosed it to the public.<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a> Thus far, it is unclear when exactly Yahoo personnel were made aware of the 2012 security breach, but many sources state the company was alerted to the security issues in the Summer of 2016.<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a> Yahoo claims to have conducted security sweeps since 2012, including one on September 9th, 2016, that led it to believe there was no reason for concern.<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a><\/p>\n<p>Yahoo CEO Marissa Mayor, has released little information regarding the controversy. However, from what little she has commented, the company seems to believe this was a state-sponsored hack.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a> A state-sponsored hack is a cyber-security attack conducted by a foreign government.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> \u201cYahoo has been stingy with the facts, but that may be at the request of U.S. law enforcement or the intelligence community,\u201d said Leo Taddeo, a former special agent in charge of the FBI\u2019s New York cyber-crime office, in an interview with The Washington Post.<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a> \u201cIf, in fact there are signs of a state actor, the authorities would definitely prefer to keep the details out of public domain. Otherwise, the hackers may get tipped off to the U.S. government\u2019s sources and capabilities.\u201d<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a><\/p>\n<p>Others wonder if the new merger with Verizon had something to do with Yahoo\u2019s reluctance to release information on the breaches to the public. Verizon is currently on track to acquire Yahoo for $4.8 billion, a figure that may be affected by the hack.<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a> In fact, a study done by Ponemon Institute found that the average cost to remediate data per user is approximately $158.<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a> According to those statistics, upwards of $70 billion would be required to mitigate the cost of this size cyber-security breach. Not surprisingly, this will likely affect the company\u2019s worth.<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a><\/p>\n<p>Senator Mark Warner, a Democrat from Virginia and cofounder of the Senate Cyber-Security Caucus, is suspicious of Yahoo\u2019s failure to disclose information that is of such \u201cvital importance\u201d \u201cto keep the public and investors informed\u201d and voiced his concerns in a letter to the U.S. Securities and Exchange Commission.<a href=\"#_ftn22\" name=\"_ftnref22\">[22]<\/a> Currently there is no federal law requiring the prompt disclosure of security breaches of this nature.<a href=\"#_ftn23\" name=\"_ftnref23\">[23]<\/a> \u201c[The] seriousness of this breach at Yahoo is huge,\u201d said Warner in a statement made Thursday afternoon.<a href=\"#_ftn24\" name=\"_ftnref24\">[24]<\/a> Recent security breaches, namely those affecting Target and Yahoo, have compelled Warner to promote legislation protecting consumers.<a href=\"#_ftn25\" name=\"_ftnref25\">[25]<\/a> In fact, Warner is \u201cworking on bipartisan legislation to create a comprehensive, nationwide, and uniform data breach standard requiring timely consumer notification for breaches of financial data and other sensitive information.\u201d <a href=\"#_ftn26\" name=\"_ftnref26\">[26]<\/a> Most states have already enacted statutes requiring disclosure to consumers.<a href=\"#_ftn27\" name=\"_ftnref27\">[27]<\/a><\/p>\n<p>For example, pursuant to Virginia Code \u00a718.2-186.6(B):<\/p>\n<p style=\"padding-left: 60px;text-align: left\">If unencrypted or unredacted personal information was or is reasonably believed to have been accessed and acquired by an unauthorized person and causes, or the individual or entity reasonably believes has caused or will cause, identity theft or another fraud to any resident of the Commonwealth, an individual or entity that owns or licenses computerized data that includes personal information shall disclose any breach of the security of the system following discovery or notification of the breach of the security of the system to the Office of the Attorney General and any affected resident of the Commonwealth without unreasonable delay.<a href=\"#_ftn28\" name=\"_ftnref28\">[28]<\/a><\/p>\n<p>While the phrase \u201cwithout unreasonable delay\u201d is largely left up to interpretation, according to the Ponemon Institute report, the average amount of time required to discover a malicious security breach is roughly 229 days. <a href=\"#_ftn29\" name=\"_ftnref29\">[29]<\/a> If Yahoo personnel have been forthcoming with their investigation, it took them nearly two years to discover this major security breach, three times the suggested average. <a href=\"#_ftn30\" name=\"_ftnref30\">[30]<\/a> One cannot help but speculate, was this really a reasonable delay in disclosure or a calculated cover-up? As new facts emerge the motive may be revealed, but until then the public is left with concerns about Yahoo\u2019s transparency.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <em>See<\/em> <em>generally <\/em>Phenom Institute, 2016 Cost of Data Breach Study: Global Analysis, at 1 (2016), http:\/\/www-01.ibm.com\/common\/ssi\/cgi-bin\/ssialias?htmlfid=SEL03094WWEN (analyzing statistics of cyber data breaches worldwide).<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>See <\/em>Ali Hedayati, <em>An Analysis of Identity Theft: Motives, Related Frauds, Techniques, and Prevention<\/em>, 4 J. of L. &amp; Conflict Resol. 1, 2\u20133 (2012), http:\/\/www.academicjournals.org\/article\/article1379859409_Hedayati.pdf<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> <em>See id <\/em>at 10.<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>See id <\/em>at 4.<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>See <\/em>Riley Walters, <em>Cyber Attacks on U.S. Companies Since November 2014<\/em>, Heritage.org, http:\/\/www.heritage.org\/research\/reports\/2015\/11\/cyber-attacks-on-us-companies-since-november-2014 (last visited October 3, 2016).<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <em>See <\/em>Judy Leary, <em>The Biggest Data Breaches in 2016, So Far<\/em>, Identity Force Blog, https:\/\/www.identityforce.com\/blog\/2016-data-breaches<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> <em>See <\/em>Kif Leswing, <em>Yahoo Confirms Major Breach \u2013 and it Could be the Largest Hack of All Time<\/em>, Business Insider (Sept. 22, 2016), http:\/\/www.businessinsider.com\/yahoo-hack-by-state-sponsored-actor-biggest-of-all-time-2016-9<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> http:\/\/www.mercurynews.com\/2016\/09\/23\/yahoo-hit-with-class-action-lawsuit-over-massive-data-breach\/<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>See <\/em>Nicole Perlroth, <em>Yahoo Says Hackers Stole Data on 500 Million Users in 2014<\/em>, N.Y. Times (Sept. 22, 2016), http:\/\/www.nytimes.com\/2016\/09\/23\/technology\/yahoo-hackers.html?_r=0<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <em>See <\/em>Reuters, <em>Yahoo is Sued for Gross Negligence Over Huge Hacking<\/em>, Fortune (Sept. 23, 2016), http:\/\/fortune.com\/2016\/09\/23\/yahoo-is-sued-for-gross-negligence-over-huge-hacking\/<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>See <\/em>Hayley Tsukayama, <em>Data Breach: What Yahoo Knew When Could Cause it Trouble<\/em>, Union-Bulletin.com, http:\/\/www.union-bulletin.com\/news\/business\/data-breach-what-yahoo-knew-when-could-cause-it-trouble\/article_0e099de4-880a-11e6-ba24-cff074054d7e.html (last visited October 3, 2016).<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> <em>See <\/em>Paul Szoldra, <em>Yahoo Won\u2019t Answer the Most Important Question About its Massive Hack<\/em>, Business Insider (Sept. 28, 2016), http:\/\/www.businessinsider.com\/yahoo-massive-hack-2016-9<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>See Account Security Issue FAQs<\/em>, Yahoo.com, https:\/\/help.yahoo.com\/kb\/account\/SLN27925.html?impressions=true (last visited October 1, 2016).<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>See <\/em>Timour Rashed, <em>State Sponsored Hacking and Cyber Security Policy<\/em>, Tim Tech Support Blog (Apr. 18, 2012), http:\/\/timourrashed.com\/state-sponsored-hacking-and-cyber-security-policy\/<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> <em>See <\/em>Hayley Tsukayama, <em>Could Yahoo be in Trouble with the SEC?<\/em>, The Washington Post (Sept. 28, 2016), https:\/\/www.washingtonpost.com\/news\/the-switch\/wp\/2016\/09\/28\/could-yahoo-be-in-trouble-with-the-sec\/<\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> <em>Id. <\/em><\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>See <\/em>Perlroth, <em>supra <\/em>note 9.<\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> <em>See<\/em> Phenom Institute Report, <em>supra <\/em>note 1 at 1.<\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> <em>See <\/em>Leswing, <em>supra <\/em>note 7.<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> <em>See Senator Warner Calls on SEC to Investigate Disclosure of Yahoo Breach<\/em>, Mark R. Warner Blog (Sept. 26, 2016, 12:15 PM), http:\/\/www.warner.senate.gov\/public\/index.cfm\/bloghome; <em>See also <\/em>Letter from Mark R. Warner, U.S. Senator, to The Honorable Mary Jo White, U.S. SEC Chair (Sept. 26, 2016) (https:\/\/www.scribd.com\/document\/325367178\/20160926-Letter-to-SEC-on-Yahoo-Breach).<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[23]<\/a> <em>See <\/em>Perlroth, <em>supra <\/em>note 9.<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[24]<\/a> <em>See <\/em>Mark R. Warner Blog, <em>supra <\/em>note 22.<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[25]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[26]<\/a> <em>Id. <\/em><\/p>\n<p><a href=\"#_ftnref27\" name=\"_ftn27\">[27]<\/a> Nat\u2019l Conf. of State Legislatures: Security Breach Notification Laws, (Jan. 4, 2016), http:\/\/www.ncsl.org\/research\/telecommunications-and-information-technology\/security-breach-notification-laws.aspx<\/p>\n<p><a href=\"#_ftnref28\" name=\"_ftn28\">[28]<\/a> Va. Code Ann. \u00a7 18.2-186.6 (2016).<\/p>\n<p><a href=\"#_ftnref29\" name=\"_ftn29\">[29]<\/a> <em>See <\/em>Ponemon Institute Report, <em>supra <\/em>note 1 at 3.<\/p>\n<p><a href=\"#_ftnref30\" name=\"_ftn30\">[30]<\/a> <em>See<\/em> Perlroth <em>supra<\/em> note 9.<\/p>\n<p>Photo Source:<\/p>\n<p>http:\/\/www.infrastructure-intelligence.com\/sites\/default\/files\/field\/image\/cyber-security.jpg<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By: Kaley Duncan, Cyber-security is a growing concern worldwide.[1] Continued increase in information sharing via the internet has left this information susceptible to hacker exploitation.[2] The motive for many cyber-attacks is to sell information gained to sites that use that information for identity theft. [3] If you are like me, your passwords are not only [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-3340","post","type-post","status-publish","format-standard","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-RS","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=3340"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3340\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=3340"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=3340"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=3340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}