Email and search engine company Yandex said today that it discovered that one of its employees was selling access to users' inboxes for personal gain.
The company, which did not disclose the employee's name, said the person was "one of three system administrators with the necessary access rights to provide technical support" for the Yandex.Mail service.
The Russian company said it is now in the process of notifying the owners of the 4,887 mailboxes that were compromised and whose access the employee was selling to third parties.

Yandex officials said they have re-secured the compromised accounts and blocked what appeared to be an authorized login. They are also asking affected account holders to change passwords .
Yandex said it discovered the incident during a "systematic review" by internal security team , without providing further details.
The Russian company said a "thorough internal investigation" of the incident is underway and that it plans to make changes to how administrative staff can access user data .
It also said there was no evidence to suggest that users' payment data was stolen during the recent incident.
Information source: zdnet.com
