Peace Sells... But Who's Buying?
Timewarp #1: Yahoo at ten, and the dump that got almost everything wrong. The dark web listing that forced Yahoo's hand was wrong about almost everything, and that is why it worked.
Hello there cyber fanatics!
I am starting a series called Timewarp. Every entry takes a round-number anniversary of something that changed this industry and asks what we actually learned, as opposed to what we tell ourselves we learned. Today is the ten year mark of Yahoo telling the world about 500 million accounts, so Yahoo goes first.
Here is the part that made me want to write it. The dark web listing that kicked this whole thing loose was wrong. Wrong year, wrong hashing, wrong size, and most likely not even a Yahoo breach. It worked anyway.
Three Bitcoin and a Bad Hash
On 1 August 2016, Motherboard's Joseph Cox reported that a seller using the handle Peace was advertising 200 million supposed Yahoo accounts on TheRealDeal. The asking price was three bitcoin. About $1,860 at the time. Peace already had a track record from the MySpace and LinkedIn dumps, so people took the listing seriously.
Peace said the data was "2012 most likely". The sample had usernames, dates of birth, some backup email addresses, and passwords hashed with MD5. Motherboard tested two dozen of the usernames and most of them were real Yahoo accounts. Then they mailed over a hundred of the sample addresses and a lot of them bounced as disabled.
Yahoo's public line was that it was "aware of a claim" and took it seriously. Which is corporate for "please stop calling us".

TheRealDeal listing for “Yahoo 200M” by peace_of_mind at 3 BTC, as published by Motherboard / Joseph Cox (1 Aug 2016). Forum-first beat only - not proof of the later ≥500M disclosure.
Sit with the economics for a second. Somebody offered 200 million records belonging to one of the biggest mail providers on earth, for less than the cost of a used laptop. That price is a confession. Nobody prices a fresh, clean, exclusive Yahoo database at $1,860. That price says old, recycled, probably mostly dead.
So Was It Yahoo?
Probably not, and this is where most anniversary posts get lazy.
Yahoo investigated the claim and concluded the 2012 data did not come from a breach of their servers. The numbers back that up. Peace's set was MD5. Yahoo said the vast majority of the 500 million accounts it later disclosed were bcrypt. Different year, different size, different hashing story. The likely explanation is that Peace assembled credential sets from other breaches, which is completely normal behavior in that market and has been for years.
One thing I will not claim. Nobody has ever publicly connected Peace to the four people the US later charged. The listing showed up before the disclosure did, and that is the whole of what we know. Everything past that is a guess, and a tidier story is not worth inventing.
So the listing was junk. And investigating that junk is how Yahoo found the real one.
They Already Knew
This is the sentence that should bother you.
In a November 2016 SEC filing, Yahoo said its own employees knew in 2014 that an intrusion had happened. The company said it did not understand the extent of it until it started investigating a separate incident around July 2016.
July 2016. That is the Peace investigation.
Read the order of events again. Yahoo's security people had knowledge of a 2014 intrusion, in 2014. Two years later a stranger on a criminal marketplace posted the wrong data at a bargain price, journalists started calling, and the resulting scramble is what finally produced a real number and a public disclosure on 22 September 2016.
The knowledge was already inside the building. What was missing was the pressure.
That disclosure said at least 500 million accounts, stolen in late 2014, by what Yahoo believed was a state-sponsored actor. Names, email addresses, phone numbers, dates of birth, hashed passwords, and in some cases security questions and answers. Yahoo said it found no evidence the actor was still in the network and that the affected system did not appear to hold payment card or bank account data.
One more thing, because everybody mixes this up. There are two Yahoo breaches. This week's anniversary is the 500 million one, from late 2014. The famous 3 billion number is a completely different hack, from August 2013. Yahoo disclosed that second one in December 2016 and called it 1 billion accounts, then raised it in October 2017 to every account the company ever had, around 3 billion. Same company, different break-in, three years apart.
The Hybrid, Officially Named
On 15 March 2017 the US Department of Justice charged four people over a conspiracy that began at least as early as 2014.
Dmitry Dokuchaev and Igor Sushchin were FSB officers in Center 18, the unit that was supposed to be Washington's counterpart on cybercrime cooperation. Alexsey Belan was a criminal hacker already sitting on the FBI's Cyber Most Wanted list. Karim Baratov was a hacker-for-hire in Canada who got paid per mailbox.
DOJ's language was that the officers "protected, directed, facilitated and paid" the criminals. They handed Belan sensitive law enforcement and intelligence information to help him with his other crimes. When a target had a mailbox somewhere other than Yahoo, they subcontracted Baratov on commission for more than 80 accounts. Baratov pleaded guilty and was sentenced in May 2018 to five years and $2.25 million. The other three never saw the inside of a US courtroom.
Dokuchaev did go to prison, and this is my favourite detail in the whole story. Russia arrested him in Moscow in December 2016, three months before the Americans charged him, and in April 2019 a Russian court gave him six years for treason. He was convicted for the wrong crime by the wrong country, and the Yahoo case had nothing to do with it.
Two officers with a budget, one specialist with a criminal side business the employer found useful, one contractor on piece rates. Source: DOJ indictment, 15 March 2017.
Look at that structure as an org chart and it is very familiar. Two people with authority and a budget. One specialist with deep access and a criminal side business that the employer tolerates because it is useful. One contractor on piece rates for the jobs the specialist cannot be bothered with. I manage nine researchers and I can tell you that is a staffing model, not a conspiracy. The state did not have to build the capability. It rented it, and paid for the parts it did not have.
Espionage is not new. Government entities hiring the criminals they are theoretically supposed to arrest, and writing it down clearly enough that a grand jury can read it back, was the new part.
Reading the Junk
Most of it is garbage. Resold combolists dressed as fresh breaches. Recycled dumps renamed after whoever is in the news. Samples that do not validate. Sellers who disappear after taking payment. If you judge a monitoring program by how many listings turn out to be real, you will shut it down inside a quarter and feel smart about it.
Yahoo is the argument against shutting it down. The listing was wrong about the year, wrong about the hashing, wrong about the size, and wrong about whose systems it came from. It still surfaced a genuine intrusion that the company had been sitting on for two years, because a wrong listing still forces someone senior to ask a real question.
So stop scoring these listings on whether they turn out to be true. Score them on what it costs you to ignore one.
So the practical version. Somebody in your organization should be reading these listings, and that person needs a route to someone who can start an investigation without filing a ticket first. If your only escalation path for "a stranger is selling something that claims to be ours" runs through a journalist calling your press office, you are already running on Yahoo's timeline.
The Circle Did Not Break
Ten years on, all three pieces are still in business. The marketplaces are still open and still full of junk with occasional gold in it. States are still renting criminals and the arrangement got more formal, not less. And companies still sit on uncomfortable findings until somebody outside makes it expensive to keep sitting.
If I had to bet, the next Yahoo-scale disclosure will follow exactly this shape. Somebody will notice first, they will be wrong about the details, and the wrongness will not matter at all.
Who in your organization is paid to read the listing? If the answer is nobody, that is your answer.
Have fun, and good luck!
Sources
- Motherboard, Yahoo 'Aware' Hacker Is Advertising 200 Million Supposed Accounts on Dark Web, 1 Aug 2016
- Yahoo Security Notice, 22 September 2016
- Tom's Guide, Yahoo Found Real Data Breach While Looking into Fake One
- DOJ, U.S. Charges Russian FSB Officers and Their Criminal Conspirators for Hacking Yahoo and Millions of Email Accounts, 15 Mar 2017
- DOJ, International Hacker-For-Hire Sentenced to 60 Months in Prison
- Yahoo Security Notice, 14 December 2016
- TechCrunch, Yahoo says all 3B accounts were impacted by 2013 breach, 3 Oct 2017
- Yahoo data breaches, Wikipedia