Yahoo’s massive data breaches triggered consolidated class-action litigation in U.S. federal court after disclosures that attackers had compromised hundreds of millions of accounts and, later, all 3 billion Yahoo accounts. Reporting on the company’s security posture said Yahoo had deprioritized defensive investments and delayed stronger measures such as broader intrusion detection and a mass password reset, while the fallout drew scrutiny from regulators, lawmakers, foreign officials, and users affected in the United States and abroad.
The legal fight expanded as a judge ruled that breach victims could pursue claims against Yahoo in the United States, then rejected a proposed settlement covering roughly 200 million people because it did not clearly show how much compensation class members would receive, how large the settlement fund effectively was, or whether attorney fees were reasonable. Yahoo later returned with a revised $118 million settlement proposal tied to the broader 3 billion-account breach, adding commitments to spend more than $300 million on information security over four years and maintain a security staff of 200 employees, while ensuring any unawarded legal fees would stay in the fund for victims rather than revert to the company.

See attribution, scope, and your downstream exposure.
12 events from the most recent confirmed update back to the earliest known activity.
Yahoo and plaintiffs presented a revised settlement valued at $118 million after the court criticized the earlier proposal. The updated deal kept any unawarded attorney fees in the fund for class members and added commitments on security spending and staffing over four years.
On preliminary review, Judge Lucy Koh refused to approve Yahoo's proposed settlement, saying it did not clearly explain victim compensation, settlement fund details, credit-monitoring costs, or the scope of the class. She also questioned the proposed attorney-fee cap and Yahoo's overall lack of transparency.
Yahoo agreed to a proposed settlement worth $50 million plus two years of free credit-monitoring services for affected users in the U.S. and Israel. Filed in federal court in San Jose, the deal covered claims tied to Yahoo's massive 2013 and 2014 breaches and awaited court approval.
A U.S. judge held that victims of Yahoo's data breaches could pursue claims against the company in the United States. The ruling allowed the litigation to move forward despite Yahoo's challenge to where claims could be brought.
Yahoo said its internal investigation found that senior executives, lawyers, and security staff knew of the 2014 breach and later account-access activity in 2015 and 2016 but failed to properly understand or investigate it. The company announced the resignation of top lawyer Ronald S. Bell, stripped CEO Marissa Mayer of her 2016 bonus and 2017 equity award, and said forged cookies had been used to access about 32 million accounts.
Yahoo and Verizon agreed to reduce the price of Verizon's acquisition of Yahoo by $350 million amid fallout from Yahoo's major breach disclosures. The revised deal reflected the material business impact of the incidents on Yahoo's sale process.
Germany publicly rebuked Yahoo over its handling of the hack and broader security practices. The criticism added international regulatory and political pressure following the breach revelations.
Multiple Yahoo data-breach class-action suits were joined together in federal court in San Jose. The consolidation formalized the civil litigation stemming from the breach disclosures.
Six Democratic U.S. senators sent a letter to Yahoo CEO Marissa Mayer seeking details on when Yahoo discovered the 2014 intrusion, why disclosure took about two years, and whether the company had received any government warning. The lawmakers said the delay was unacceptable given the sensitivity of the stolen account data.
Yahoo announced that a 2014 attack had exposed data from about 500 million user accounts and said the intrusion was linked to a state-backed actor. The disclosure triggered FBI scrutiny, political pressure, and litigation.
In 2014, Yahoo brought in Alex Stamos as CISO as part of efforts to improve its security posture. Reporting later said internal disagreements limited how far some proposed security changes went.
Yahoo was compromised in 2014 in an intrusion that later became the company's first major publicly disclosed breach in this saga. The incident reportedly went undetected for about two years before disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
11 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourceweb.archive.org
Open sourceengadget.com
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourceweb.archive.org
Open sourcenytimes.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.