If Yahoo had indeed positively identified the breach to have originated from a 'state-sponsored actor', it is possible that their thinking was something along the lines of "Resetting the passwords wouldn't help us much anyway against someone with so many resources."
Of course, I'm just speculating based on what I see in news reports. Perhaps the 'state-sponsored' actor was just PR spin to save face? I really just don't know what to think.
Of course, I'm just speculating based on what I see in news reports. Perhaps the 'state-sponsored' actor was just PR spin to save face? I really just don't know what to think.