453,000 Yahoo passwords exposed, hackers claim
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
Nearly half a million usernames and passwords apparently taken from a Yahoo service have been posted online by hacking group D33Ds Company last night. The leak, which was picked up by Ars Technica , is believed to contain credentials taken from Yahoo's Voices social network/blogging service.
Yahoo has yet to comment on the leak or confirm which service was attacked, although it has said that it is preparing a statement.
According to the D33Ds website, the attack was carried out via a union-based SQL injection method. This is a relatively trivial technique which involves inserting code into URL search strings. Security experts at Trusted Sec have expressed alarm that “the passwords were stored completely unencrypted and the full 400,000+ usernames and passwords are now public”.
John Koetsier, at VentureBeat , believes that the password list may not be up to date. But neither is it necessarily a complete dump of what the hackers uncovered. The long and short of it is that if you have a Yahoo account, it's probably a good idea to change your password and make sure you don't use the same password for different services.
Personally, I can't recommend using an encrypted password locker like LastPass enough. This is an online vault for storing long, randomly generated passwords that are unique for each site you use. There's plenty of different tools like this around, including the open source KeePass and Clipperz , and I'd encourage you to start using one today.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.

