Facebook Linkedin
  • About us
  • Advisory Board
  • Careers
  • Write for CISO MAG
  • Editorial Calendar
Search
Sunday, July 6, 2025
  • About us
  • Advisory Board
  • Careers
  • Write for CISO MAG
  • Editorial Calendar
Facebook Linkedin
CISO MAG  - News and Updates| Cyber Security Magazine CISO MAG | Cyber Security Magazine
Cisomag banner-Essentials
CISO MAG  - News and Updates| Cyber Security Magazine CISO MAG  - News and Updates| Cyber Security Magazine
  • About us
  • Advisory Board
  • Careers
  • Write for CISO MAG
  • Editorial Calendar
Home News How Yandex Was Impacted by an Inside Job
  • News
  • Threats

How Yandex Was Impacted by an Inside Job

An employee at Yandex compromised thousands of users’ email accounts for personal gain. This incident shows that even system administrators cannot be trusted. It makes a case for a ZERO-TRUST policy.

By
CISOMAG
-
February 16, 2021
Facebook
Twitter
Pinterest
WhatsApp
    Yandex suffers insider attack

    Yandex, a popular internet company in Europe and search platform in Russia, disclosed an insider attack that affected thousands of its employees’ email systems. In an official release, the company revealed that one of its system administrators had illicitly accessed users’ mailboxes for personal gain.

    “This employee was one of three system administrators, who had the access privileges to provide technical support for mailboxes,” said Yandex.

    In total, the employee compromised over 4,887 mailboxes. However, Yandex confirmed that no payment details were affected in the incident. While a detailed internal investigation of the breach is underway, Yandex reported the incident to the law enforcement authorities. The security team also blocked unauthorized access to the compromised mailboxes and notified the affected users about the breach. The users were asked to change their account passwords immediately to avoid any further loss.

    “A thorough internal investigation of the incident is underway, and Yandex will be making changes to administrative access procedures. This will help minimize the potential for individuals to compromise the security of user data in the future. The company has also contacted law enforcement,” Yandex added.

    Earlier, Yandex was hacked by Western intelligence. According to a report, the alleged hack occurred to search for information on how Yandex authenticates user accounts. It was found that a malware dubbed “Regin” was used to penetrate the systems. Regin is a tool that is used by the “Five Eyes,” an intelligence nexus that comprises the U.S., Britain, Australia, New Zealand, and Canada.

    Insider attacks can impact an organization in a variety of ways. From high penalties to brand image damage, it whips multiple blows on companies. Some of the consequences include loss of customers’ trust, financial damage, loss of intellectual properties, a huge impact on the company’s reputation, and high worth fines from data regulators.

    Related Story: Insider Threats: A Byproduct of the New Normal

    • TAGS
    • compromised email account
    • Cyberattacks
    • Cybercriminals
    • cybersecurity
    • email accounts
    • Insider attack
    • Insider attacks
    • insider job
    • insider threats
    • Yandex
    • Yandex data breach
    Facebook
    Twitter
    Pinterest
    WhatsApp
      Previous articleEpisode #8: Intel Labs’ Breakthrough Research on Data Privacy and Encryption Technologies
      Next articleEC-Council Unveils the Certified Ethical Hacker Hall of Fame 2021
      CISOMAG
      CISOMAG
      https://cisomag.com/

      RELATED ARTICLESMORE FROM AUTHOR

      PSTI IoT Bill, Common IoT Attacks
      Features

      3 Common IoT Attacks that Compromise Security

      SIM Swapping
      News

      FBI Issues a Lookout for SIM Swapping Attacks

      remote work, Remote workforce security
      News

      How Remote Work Increase Digital Anxiety



      Cyber Career Starter Scholarship

      Latest Issue is Out!

      Ciso mag jan
      cciso_sidebar
      boxbanner

      FOLLOW US FOR MORE UPDATES


      CYBER SHOTS
      Quick, punchy updates on Cyber trends, news and links to free resources. Only via Telegram and Signal. Join the groups now!
      Click Here Click Here
      Cybersecurity News and Updates, Magazine
      CISOMAG is the handbook for Chief Information Security Officer (CISO)s, CXOs, and every stakeholder of safe internet.
      Contact us: [email protected]
      Facebook Linkedin

      EVEN MORE NEWS

      CyberSecID Conference 2025 (CSID2025)

      July 4, 2025

      World AI Show – Indonesia

      July 4, 2025

      Cyber Security Expo Europe

      June 19, 2025

      POPULAR CATEGORY

      • News2554
      • Threats1657
      • Features592
      • Partnerships215
      • Governance191
      • Startups161
      • Upcoming Events122
      • Terms of Use
      • Privacy Policy
      • Advertise with us
      • Contact Us
      • MASTERCLASS
      © CISOMAG 2024
      We Care
      Ensuring that you get the best experience is our only purpose for using cookies. If you wish to continue, please accept. You are welcome to provide a controlled consent by visiting the cookie settings. For any further queries or information, please see our privacy policy.
      Do not sell my personal information.
      Cookie SettingsAccept
      Manage consent

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
      CookieDurationDescription
      cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
      cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
      cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
      cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
      cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
      viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
      Functional
      Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
      Performance
      Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
      Analytics
      Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
      Advertisement
      Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
      Others
      Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
      SAVE & ACCEPT
      MORE STORIES
      Upcoming Events

      CyberSecID Conference 2025 (CSID2025)

      CISO MAG - July 4, 2025 0
      Date: July 9-10, 2025 Location: Shangri La, Jakarta, Indonesia CyberSecID Conference 2025 (CSID2025) is a premier gathering of security professionals from...