Breach Intelligence Report 25 Jul 2022

The Yahoo Voices Dump: 386K Stolen Credentials Hit the Dark Web

HEROIC
HEROIC Threat Intelligence Team
Email Address Passwords
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 386,539
Source Type Database
Origin Darkweb
Password Type plaintext

Yahoo! Voices was Yahoo's online publishing platform where users could write and publish articles. In July 2012, attackers exploited a SQL injection vulnerability in the Voices platform and extracted 386,539 user account records. What made this breach especially damaging was that Yahoo stored passwords in plaintext, meaning no cracking was required. Attackers had immediate access to working email and password pairs from the moment the breach occured. Analysis at the time found that 59% of affected users also reused those same passwords on accounts compromised in the Sony breach, demonstrating just how far password reuse amplifies a single incident.


Why Yahoo Voices Breach Is Dangerous

Plaintext password storage is the worst possible approach to credential security. When a breach like this happens, attackers do not need to crack hashes or run password cracking software. They have the actual password immediately. For the 386,539 people whose credentials were exposed, any account using that same email and password combination was definitly compromised the moment this data was shared online. Yahoo Voices was a public writing platform, so these accounts were tied to real names and publicly visible profiles.

What Was Exposed in the Yahoo Voices Leak

  • Email Address
  • Passwords (plaintext)

Why This Yahoo Data Puts You at Risk

Even if you no longer have a Yahoo Voices account, the email address and password from 2012 may still be the same combination you use elsewhere. Research published at the time of this breach showed that over half of these users reused their Yahoo Voices password on other services. If you had an account on Yahoo Voices in 2012 and haven't changed passwords across your accounts since then, there is a real risk that old credentials are still working against accounts you actively use today.


How SQL Injection Breaches Work

SQL injection is one of the most common and oldest web attack techniques. It works by inserting malicious database commands into input fields on a website. If the developer did not properly validate and sanitize user input, the attacker can retrieve data from the underlying database. At Yahoo Voices, this vulnerability allowed the attacker to pull the entire user credential table. The attack was relatively straightforward, but the damage was serious because passwords were not hashed or encrypted at all, making recovery immediatly possible for every record in the dump.


Check If Your Data Was Exposed

HEROIC's free breach search checks your email against 400 billion+ compromised records, including the Yahoo Voices 2012 dataset. Search now to see if your account was included, and if it was, change that password on every account where you've used the same combination since 2012.

Breach Breakdown

Domain N/A
Leaked Data Email Address, Passwords
Password Types plaintext
Date Leaked 25 Jul 2022
Check in 5 seconds

386,539 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,733 scanned today
Breach Rank #2,272 by affected users
Impact Score
15
sensitivity + scale + recency
Est. Financial Impact $2.8M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance