The Yahoo Voices Dump: 386K Stolen Credentials Hit the Dark Web
Yahoo! Voices was Yahoo's online publishing platform where users could write and publish articles. In July 2012, attackers exploited a SQL injection vulnerability in the Voices platform and extracted 386,539 user account records. What made this breach especially damaging was that Yahoo stored passwords in plaintext, meaning no cracking was required. Attackers had immediate access to working email and password pairs from the moment the breach occured. Analysis at the time found that 59% of affected users also reused those same passwords on accounts compromised in the Sony breach, demonstrating just how far password reuse amplifies a single incident.
Why Yahoo Voices Breach Is Dangerous
Plaintext password storage is the worst possible approach to credential security. When a breach like this happens, attackers do not need to crack hashes or run password cracking software. They have the actual password immediately. For the 386,539 people whose credentials were exposed, any account using that same email and password combination was definitly compromised the moment this data was shared online. Yahoo Voices was a public writing platform, so these accounts were tied to real names and publicly visible profiles.
What Was Exposed in the Yahoo Voices Leak
- Email Address
- Passwords (plaintext)
Why This Yahoo Data Puts You at Risk
Even if you no longer have a Yahoo Voices account, the email address and password from 2012 may still be the same combination you use elsewhere. Research published at the time of this breach showed that over half of these users reused their Yahoo Voices password on other services. If you had an account on Yahoo Voices in 2012 and haven't changed passwords across your accounts since then, there is a real risk that old credentials are still working against accounts you actively use today.
How SQL Injection Breaches Work
SQL injection is one of the most common and oldest web attack techniques. It works by inserting malicious database commands into input fields on a website. If the developer did not properly validate and sanitize user input, the attacker can retrieve data from the underlying database. At Yahoo Voices, this vulnerability allowed the attacker to pull the entire user credential table. The attack was relatively straightforward, but the damage was serious because passwords were not hashed or encrypted at all, making recovery immediatly possible for every record in the dump.
Check If Your Data Was Exposed
HEROIC's free breach search checks your email against 400 billion+ compromised records, including the Yahoo Voices 2012 dataset. Search now to see if your account was included, and if it was, change that password on every account where you've used the same combination since 2012.
Breach Breakdown
386,539 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds