Entra ID & IdentityIncident TeardownsRetrospectives

Yahoo's Billion-Account Breach Disclosure (Dec 2016): The Case for MFA Everywhere

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2016, written in 2026 with the benefit of hindsight.

In December 2016, Yahoo disclosed that data from roughly one billion user accounts had been stolen in 2013. Months earlier it had disclosed a separate 2014 breach of 500 million accounts. In 2017 the company revised the 2013 figure to every account it had at the time — about three billion.

What was taken

Names, email addresses, phone numbers, dates of birth, hashed passwords and, in some cases, security questions and answers. Many of the passwords were protected with MD5, an outdated hashing method that is easy to crack at scale.

Why it mattered beyond Yahoo

Yahoo itself was only part of the story. People reuse passwords. A billion email-and-password pairs entering criminal markets meant credential-stuffing attacks against every other service those people used — including corporate email.

The breach also showed how slowly the consequences arrive. The data was stolen in 2013, disclosed in 2016, and still circulating for years afterwards. It eventually affected Yahoo's acquisition price, reduced by $350 million when Verizon bought it.

Lessons for Microsoft 365 and cloud identity

  • Passwords alone are not a control. Any user's password should be assumed to be on a list somewhere.
  • Multi-factor authentication is the minimum. Blocking sign-ins that lack a second factor neutralizes most credential-stuffing attempts.
  • Security questions are not a second factor. They are often public or guessable — and they were stolen too.
  • Watch for leaked credentials. Entra ID Protection can flag users whose credentials appear in known leaks.

In hindsight

The Yahoo breaches pushed MFA from "nice to have" toward the default it is today. A decade later, the remaining gap is the quality of the second factor: phishing-resistant methods such as passkeys are the next step.

yahoo data breachYahoo breach2016

More on this story