
What happened
In December 2014, according to the Securities and Exchange Commission's April 2018 order, hackers described as Russian actors stole data associated with hundreds of millions of Yahoo user accounts, including usernames, email addresses, phone numbers, birth dates, and encrypted passwords and security-question answers. Yahoo's own security team learned of the intrusion within days. The SEC's order describes a company that, despite that early internal awareness, did not disclose the breach to investors in any securities filing for close to two years, only doing so as it worked to close the sale of its operating business to Verizon in 2016.
The order finds that during that period Yahoo's periodic reports and risk-factor disclosures did not mention the breach or treat it as a material risk, and that relevant information was not shared internally with the company's auditors or outside counsel in a way that would have supported an accurate disclosure decision. On 24 April 2018, the SEC announced that Altaba, the entity that had held Yahoo's non-operating assets after the Verizon sale, agreed to pay a $35 million penalty to settle the resulting charges, without admitting or denying the findings.
Confidence and limits
The order is a settled enforcement action, not a litigated finding after trial, and the company resolved it without admitting the SEC's specific findings, a real limit even though the settlement is a matter of public record. The order describes Yahoo's internal knowledge and disclosure practices as reconstructed by SEC investigators from company records, not as facts established through adversarial testimony, and it does not value the harm to individual users beyond the securities-fraud framing of the case.
Why it mattered
Until this case, breach disclosure was treated as a consumer-notification and public-relations question rather than a securities-law one. The SEC's action established that a known, material incident sitting quietly in a company's files while investors traded its stock and a sale proceeded could itself be a securities violation, independent of how well the company later notified consumers. That reframing is one reason the SEC later adopted formal rules, effective from 2023, requiring public companies to disclose material cybersecurity incidents on a fixed timeline, a development this article's sources confirm without describing in detail.
Defensive takeaway
Make sure your organisation's process for assessing whether an incident is material for securities-disclosure purposes is documented, involves legal and finance functions alongside security, and does not depend on the same team that would prefer the incident stay quiet.
- Does your incident-response process include a defined trigger for looping in legal, finance and, where applicable, securities-disclosure counsel?
- Could a known security incident sit in your organisation for months without reaching the people responsible for public disclosures?
- If your organisation were being acquired or going public, would your standard disclosure review catch an unresolved past incident?
The two-year gap between Yahoo's internal knowledge of its breach and any public disclosure is the detail that made this a securities case rather than only a consumer-protection story, and it remains a reference point for how far a company's internal information barriers can delay a decision regulators expect to be made quickly.
Make sure your organisation's process for assessing whether an incident is material for securities-disclosure purposes is documented, involves legal and finance functions alongside security, and does not depend solely on the team that would prefer the incident stay quiet.
The account rests on the SEC's own settled enforcement order, a primary regulatory document; Altaba resolved the matter without admitting or denying the findings, so it should be read as the regulator's reconstruction of Yahoo's internal knowledge and disclosure practices rather than a fact established through contested litigation.
Sources & reading trail
Confirms the SEC's charge that Yahoo/Altaba failed to disclose the 2014 breach for roughly two years, and the $35 million settlement.
court-or-regulator-primary · Source published: 24 April 2018 · Retrieved: 16 September 2026
Sets out the SEC's specific findings on Yahoo's internal awareness of the breach, its disclosure controls failure, and the settlement terms.
court-or-regulator-primary · Source published: 24 April 2018 · Retrieved: 16 September 2026
Establishes that the SEC later adopted formal rules requiring public companies to disclose material cybersecurity incidents on a fixed timeline.
government-primary · Source published: 26 July 2023 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.