Yahoo! agrees to pay $35mn penalty for data breach

Image
IANS Washington
Last Updated : Apr 25 2018 | 11:30 AM IST

Yahoo!, now known as Altaba, which was charged with failing to disclose a massive data breach, has agreed to pay $35 million in penalty to the US Securities and Exchange Commission (SEC).

In a statement late on Tuesday, the SEC said the entity formerly known as Yahoo! Inc. has agreed to settle charges that it misled investors by failing to disclose one of the world's largest data breaches in which hackers stole personal data relating to its three billion users.

According to the SEC's order, within days of the December 2014 intrusion, Yahoo's information security team learned that Russian hackers had stolen what the security team referred to internally as the company's "crown jewels".

There "crown jewels" were usernames, email addresses, phone numbers, birthdates, encrypted passwords, and security questions and answers for hundreds of millions of user accounts.

The fact of the breach was not disclosed to the investing public until more than two years later, when in 2016 Yahoo was in the process of closing the acquisition of its operating business by Verizon Communications, Inc, the statement read.

"We do not second-guess good faith exercises of judgment about cyber-incident disclosure. But we have also cautioned that a company's response to such an event could be so lacking that an enforcement action would be warranted. This is clearly such a case," said Steven Peikin, Co-Director of the SEC Enforcement Division.

The SEC statement said that when Yahoo filed several quarterly and annual reports during the two-year period following the breach, the company failed to disclose the breach or its potential business impact and legal implications.

"Instead, the company's SEC filings stated that it faced only the risk of, and negative effects that might flow from, data breaches," it added.

In addition, the SEC found that Yahoo did not share information regarding the breach with its auditors or outside counsel in order to assess the company's disclosure obligations in its public filings.

Verizon acquired Yahoo's operating business in June 2017 for $4.48 billion. Yahoo has since changed its name to Altaba Inc.

--IANS

na/pgh/

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Apr 25 2018 | 11:22 AM IST

Next Story