If you use any Yahoo services, here's what to do following the massive breach

It isn't just your email.
 By 
Kerry Flynn
 on 
The Yahoo! logo
A Yahoo! logo is shown on a screen during a keynote address by Yahoo! President and CEO Marissa Mayer at the 2014 International CES at The Las Vegas Hotel & Casino on January 7, 2014 in Las Vegas, Nevada. Credit: Ethan Miller/Getty Images

If you use Yahoo Mail or any of its services (Tumblr, Flickr, Fantasy Football), you need to act now.

The company confirmed on Thursday a massive data breach that affected at least 500 million user accounts.

According to a long investigation that left users unaware for years, leaked account information may include names, email addresses, telephone numbers, dates of birth, hashed password, encrypted or unencrypted security questions and answers. That means passwords may not have been leaked, but it doesn't mean you shouldn't change them.


You May Also Like

Yahoo is expected to notify any potentially affected users, but anyone can follow these steps to better secure their accounts.

1. Update your Yahoo accounts

Yahoo has invalidated unencrypted security questions of those users it believes have been affected. Affected users will need to update their accounts, but anyone should go and change their password, especially if it hasn't been updated since 2014 when the breach occurred.

2. Change your passwords, security questions that match Yahoo's

If you use the same or similar passwords and security questions on multiple services, those have potentially now been exposed. Take this as an opportunity to do what you should probably have already done -- go to those accounts and change those questions.

Take this data breach, and the many breaches that have come before it, as a lesson to use different passwords on the service you use.

3. Use a password manager like LastPass

Using the same password is easy. Keeping track of passwords can be difficult. You can eliminate that burden by using a password management system like LastPass, 1Password and Dashlane.

These password managers only require users to have one master password and then suggests, encrypts and stores passwords for other sites and services.

4. Enable two-step authentication

Two-step authentication or verification is one of the best and easiest ways to provide an additional level. By enabling this service, you can request to receive a text message or call to your phone that includes a string of numbers you need to enter before logging in.

For Yahoo accounts, you can find the instructions here. You should also do this for all your other accounts on everything you use, everything you ever will use, and probably anything your kids, relatives or even casual work acquintances use.

5. Use Yahoo Account Key

Yahoo offers its own service called Account Key that eliminates the need to remember a password. Instead, users receive a notification on their smartphone and can tap yes to sign in.

You can set up Account Key here.

6. Stop using Yahoo

The hack is over -- well, it was actually done back in 2014. But this also provides an opportunity to reconsider why you use Yahoo. There are plenty of other email clients like Gmail and Outlook. For photo storage, you can try 500px instead of Flickr.

Topics Yahoo

Mashable Image
Kerry Flynn

Kerry Flynn is a business reporter for Mashable covering the tech industry. She previously reported on social media companies, mobile apps and startups for International Business Times. She has also written for The Huffington Post, Forbes and Money magazine. Kerry studied environmental science and economics at Harvard College, where she led The Harvard Crimson's metro news and design teams and played mellophone in the Band. When not listening to startup pitches, she runs half-marathons, plays with puppies and pretends to like craft beer.

Mashable Potato

Recommended For You

Panera Bread breach: ShinyHunters claims hack of 14 million customers' data
Panera Bread logo on storefront

Instagram denies data breach: So what's up with those sketchy change password emails?
instagram logo against a black background

Yahoo's new AI search tools support the open web, unlike others (cough, Google, cough)
screenshot of yahoo scout homepage

Moltbook is a 'security nightmare' waiting to happen, expert warns
moltbook website appears on phone screen

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


Wordle today: Answer, hints for April 2, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!