Skip to main content
  1. Home
  2. Computing
  3. News

Yahoo is warning users over state-sponsored cookie-forging attacks

Add as a preferred source on Google

Yahoo’s security woes continue with the company sending out a fresh warning to users over hacked accounts at the hands of allegedly state-sponsored actors.

In an email to users, Yahoo said it has identified evidence of cookie-forging attacks on some accounts, which would allow attackers to access an account without re-entering a password. The email was only sent to accounts that Yahoo believes have been affected by these intrusion attempts so we don’t know how many people have been impacted.

Recommended Videos

“Our outside forensic experts have been investigating the creation of forged cookies that could allow an intruder to access users’ accounts without a password,” the email reads. “Based on the ongoing investigation, we believe a forged cookie may have been used in 2015 or 2016 to access your account.”

It is believed that hackers obtained Yahoo’s source code for creating cookies. The company’s forensics team has invalidated any corrupted cookies it found.

It’s not clear what evidence Yahoo has to suggest these cookie forging attempts were state-sponsored. However, Yahoo has been the victim of at least two major hacks that were disclosed in the last few months for which it pointed the finger at possible hackers acting on behalf of a government.

The numerous data breaches at the web firm included 500 million accounts compromised in 2014 and up to 1 billion accounts compromised in 2013. But it wasn’t until last year that these mega breaches — as they’ve been dubbed — came to light. Yahoo is now currently under investigation by the Securities and Exchange Commission over why it waited years before disclosing the details of the hacks.

The security blunders could be costly for Yahoo as Verizon, its purchaser, has since sought a price tag reduction between $250 million and $350 million (off the original $4.83 billion offer), as it was unaware of these breaches when the offer was made.

Jonathan Keane
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
The size of a credit card: This fully functional computer even packs an e-ink screen
This credit card-sized computer packs Wi-Fi, NFC, and an e ink display
Muxcard

A developer has built a remarkably thin computer that is almost the same size and thickness as a standard credit card, potentially opening the door to a new category of ultra-portable computing devices.

Called the “Muxcard,” the experimental device combines a fully functional microcomputer, wireless connectivity, NFC support, sensors, and an E Ink display into a body measuring just 1mm thick - thin enough to fit inside a regular wallet alongside bank cards. The project, created by GitHub user “krauseler,” has quickly drawn attention from the maker and hardware enthusiast community for pushing the physical limits of compact electronics.

Read more
If your router or drone maker is banned in the US, it will get an update lifeline until 2029
Your “banned” router isn’t dead yet, says the FCC
Drone

The Federal Communications Commission has extended a key waiver allowing certain foreign-made routers, drones, and drone components to continue receiving software and firmware updates in the United States until at least January 1, 2029.

The move comes after growing concerns that millions of already-deployed devices could become cybersecurity risks if manufacturers were suddenly blocked from issuing security patches and compatibility updates. The decision was announced through the FCC’s Office of Engineering and Technology (OET), which also expanded the scope of the waiver to cover additional software-related changes needed to maintain device functionality.

Read more
AI-pilled graduates are not a big hit for finance jobs with their shallow ideas
Turns out ChatGPT can’t survive every finance interview
Artificial Intelligence

Artificial intelligence may be transforming the financial industry, but some firms are beginning to push back against a growing trend: graduates who rely too heavily on AI tools without demonstrating deeper analytical thinking.

According to a report by The Financial Times, the issue recently surfaced through experiences shared by senior finance professionals, including one New York financier who described his company’s 2025 interns as the first group of “true AI natives.” These students had grown up using both digital platforms and generative AI systems, and initially appeared highly capable during recruitment.

Read more