Case ID
Yahoo 2013-2014: 3 billion accounts, the largest breach in history.
Two separate state-sponsored intrusions, disclosed only years later during Yahoo's sale to Verizon, compromised every Yahoo account in existence: all 3 billion. It remains the largest data breach ever recorded by account count. The financial consequences ran across a rare four-way spread, a reduced acquisition price, a consumer class action, a regulatory penalty, and a shareholder-derivative recovery, each of which set a precedent. Disclosed cost passes $470M, though per record it is one of the cheapest mega-breaches on file because notification came so late.
Accounts exposed
3B
All Yahoo accounts (2013 breach)
Disclosed cost
$470M+
Verizon cut + settlements
Verizon price cut
$350M
$4.83B to $4.48B, Feb 2017
SEC penalty
$35M
First breach-disclosure fine ever
Section YHO.1
Two breaches, disclosed years late
There were two distinct incidents. The first, in August 2013, compromised all 3 billion Yahoo user accounts. The second, in 2014, was a separate state-sponsored intrusion that stole data from more than 500 million accounts. Neither was disclosed publicly at the time.
Yahoo first disclosed the 2014 breach in September 2016, mid-way through its agreement to sell its operating business to Verizon, putting the figure at 500 million accounts. In December 2016 it disclosed the separate 2013 breach, initially estimated at 1 billion accounts, then the largest breach ever reported. In October 2017, after the Verizon deal had closed, Yahoo revised the 2013 figure upward again: the breach had in fact hit every account the company had ever issued, all 3 billion.
The stolen data included names, email addresses, telephone numbers, dates of birth, hashed passwords (the majority bcrypt, some using the weaker MD5), and, critically, security questions and answers, some stored unencrypted. Payment-card and bank-account data were not in the affected systems. In the 2014 intrusion the attackers used stolen credentials and Yahoo's own Account Management Tool to forge web cookies, allowing them to access roughly 32 million accounts without a password, a technique that made the intrusion both durable and hard to detect.
Section YHO.2
The $470M+ cost composition
| Cost line item | Amount | Source |
|---|---|---|
| Verizon acquisition price reduction | $350M | Verizon / Yahoo SEC 8-K, February 2017 |
| Consumer class-action settlement | $117.5M | In re Yahoo! Inc. Customer Data Security Breach Litigation, N.D. Cal. (final approval 2020) |
| SEC penalty (failure to disclose) | $35M | SEC cease-and-desist order, 24 April 2018 (Altaba, f/k/a Yahoo) |
| Shareholder-derivative settlement | $29M | Yahoo derivative litigation, settlement approved January 2019 |
| Total documented consequences | ~$531.5M | Sum of the four line items above |
The commonly cited "$470M+" figure reflects the two largest components, the $350M Verizon price reduction and the $117.5M consumer settlement. Adding the $35M SEC penalty and the $29M derivative settlement brings the documented total to roughly $531.5M. The $350M is a reduction in the price an acquirer paid rather than a cash penalty, so treatments that count only cash outflow report a lower figure. Yahoo also does not have a clean post-breach 10-K cumulative-cost line, because the operating company was absorbed into Verizon and the remaining shell was renamed Altaba.
Section YHO.3
The Verizon deal: breach cost priced into M&A
Verizon agreed in July 2016 to buy Yahoo's operating business for $4.83 billion. When the breaches surfaced during due diligence, Verizon used the disclosures to renegotiate. In February 2017 the two companies announced a $350 million reduction, cutting the price to $4.48 billion, a 7.25% discount, and the deal closed in June 2017. It is the most-cited single example of breach cost flowing directly through a company's valuation rather than through fines or litigation.
The renegotiation also restructured post-closing liability. Verizon and the remaining Yahoo entity (renamed Altaba) agreed to share certain cash liabilities from government investigations and third-party litigation relating to the breaches, while Altaba retained sole responsibility for the SEC matter and the shareholder litigation. The episode is now standard teaching material in M&A due diligence: cybersecurity posture is a valuation input, and undisclosed breaches are a repricing event.
Section YHO.4
The first SEC breach-disclosure penalty
On 24 April 2018 the SEC announced a $35 million penalty against Altaba, the entity formerly known as Yahoo! Inc., to settle charges that Yahoo had misled investors by failing to disclose the 2014 breach for nearly two years. Yahoo's information-security team knew of the intrusion and its attribution to a state-sponsored actor within days, yet the company's public filings across 2014 to 2016 disclosed only the risk of a potential breach, not the fact that a massive one had already happened.
It was the first SEC enforcement action ever brought for failing to disclose a data breach. It established that a known, material breach is a reportable event under the securities laws, not merely an operational risk factor, and it directly informed the SEC's later cybersecurity disclosure rulemaking (Item 1.05 of Form 8-K, effective December 2023).
Section YHO.5
Attribution, prosecutions, and governance fallout
In March 2017 the DOJ indicted four people over the 2014 breach: two officers of Russia's Federal Security Service (FSB), Dmitry Dokuchaev and Igor Sushchin, and two hired hackers, Alexsey Belan and Karim Baratov. It was the first time the United States charged Russian government officials with cyber offenses. Only Baratov, a Canadian citizen, was arrested; he pleaded guilty in November 2017 and in May 2018 was sentenced to five years in prison and a $250,000 fine. The FSB officers and Belan remain in Russia, beyond US reach.
The governance consequences were their own precedent. In January 2019 Yahoo settled a shareholder-derivative suit for $29 million, funded by directors-and-officers insurance, the first time shareholders recovered monetary damages in a data-breach derivative action. An internal investigation faulted senior management and legal for failing to escalate the 2014 intrusion; Yahoo's general counsel resigned, and CEO Marissa Mayer forfeited her 2016 annual bonus and 2017 equity grant. The Verizon transaction closed in June 2017; the remaining Yahoo entity became the holding company Altaba, which wound down over the following years.
Section YHO.6
Why 3 billion records cost so little per head
Spread across 3 billion accounts, the ~$470M disclosed cost works out to roughly $0.16 per record, orders of magnitude below IBM's per-record benchmarks. That is the fixed-cost amortisation effect at extreme scale: notification, forensics, and legal cost do not scale linearly with record count, so mega-breaches always show low per-record cost. Yahoo sits at the far end of that curve for two additional reasons. Notification came years after the intrusions, collapsing the real-time response cost, and the exposed data was account-credential data rather than the payment-card or medical data that drives the highest per-record settlements. It is the clearest case in the register that "largest breach" by record count and "most expensive breach" by cost are entirely different rankings.
Cross-references
Industry / Technology
→Sector context: why tech-firm breaches route cost through M&A and IP loss.
Regulation / SEC Item 1.05
→The breach-disclosure rule the Yahoo $35M penalty helped inspire.
Cost / Per record
→Why Yahoo's $0.16 per record is the register's cheapest at scale.
Cost / Class-action settlement
→Per-plaintiff economics: Yahoo $117.5M across breaches 2012-2016.
Case / Marriott 2018
→The other 500M-record breach disclosed during a corporate transaction.
Index / All breach cases
→16 verified mega-breaches.
Schedule F / Reference Q&A
Frequently Asked Questions
Primary source:Yahoo 2013-2014 breach data from Verizon/Yahoo SEC 8-K filings (Feb 2017), the SEC cease-and-desist order against Altaba (24 April 2018), In re Yahoo! Inc. Customer Data Security Breach Litigation (N.D. Cal., final approval 2020), the Yahoo shareholder-derivative settlement approved January 2019, and the DOJ indictment and sentencing records for United States v. Dokuchaev et al. (2017-2018).