Me too Cats. I think they will. The passwords are worth what? I mean, users have to come up with a new one, but in the end, what do the proud owners of old passwords of never used accounts really have?
Yahoo isn't just sitting back and watching and allowing hacks to happen. The company itself and the employees failed like other times. However, please let's remember how much of this there is and how many times it's happened to other companies, including Microsoft and literally everyone else.
Yahoo! is a community that is trying to define itself and its niche and place on the internet of things. It's a good thing and a good idea. Good ideas never lose in the long run, so I am sure Yahoo! will recover. Anyway, I'm not going to blame the company. They got big back in the 90s to mid 2000s, so hackers made the site a bullseye for hacks. Still Yahoo! will be bullet-proof someday. I know it's not popular to say so about this, but I do believe it on this one really. Good Yahoo! employees aren't the hackers after all.
I see your point - but for the huge amount of users who don't change their password- it gives the crooks an easier way to send out large amounts of Malicious spam (or spam in general), which in theory spreads malware further and affects the whole 'ecosystem' if you look at it from a global theory. Another infected PC is hijacked and is used as part of a botnet to seek out vulnerable PC's to infect....
I cannot count the times where I get a phone call or someone asking me to look at this email from someone they know that contains nothing but a url in the body of the message (and the sender domain is @yahoo.com) - and of course it either is detected as malicious in VirusTotal then, or a week later.
Their rationale:
Well, it says it's from "Insert Friend or Relative's Name", so why shouldn't I open it.
I am not trying to be rude or sarcastic. In reality think of the amount of users (family, people who may be older or retired and cybersecurity was never a big training objective in their company).
People wonder what to do, either abandon their accounts all together for fear of getting a virus by even logging in to cange their password. (If a site is serving malware via ads, then this has merit.....
Cough...
It's complicated.