YAHOO▊
Organization dossier SEC order 3-18448 · Altaba Inc. Status: record still stands
Every account it ever created got breached — ultimately all three billion, the largest breach on record. The company knew of a second, separate intrusion for nearly two years and told no one, right up until it was selling itself to Verizon. When investors finally learned, the SEC wrote the first fine in its history for hiding a breach from them: $35 million.
As CEO, these thefts occurred during my tenure, and I want to sincerely apologize to each and every one of our users.
Marissa Mayer, former Yahoo CEO, in her prepared statement to the U.S. Senate Committee on Commerce, Science, and Transportation, Nov 8, 2017
Yahoo was the victim of criminal state-sponsored attacks on its systems resulting in the theft of certain user information … We now know that Russian intelligence officers and state-sponsored hackers were responsible.
Marissa Mayer, same statement, Senate Commerce Committee, Nov 8, 2017
- ENTITY
- Yahoo! Inc., later Altaba Inc. — the residual holding company that retained the breach liability after Verizon bought the operating business in 2017 FACT
- PRINCIPAL
- Marissa Mayer, CEO 2012–2017 — the company's public voice; the enforcement below is against the company, not a personal indictment FACT
- THE BREACHES
- A 2013 intrusion revised upward to ~3 billion accounts (the largest known) · a separate 2014 intrusion of ~500 million FACT
- THE DRAMA
- Nearly two years of non-disclosure through quarterly and annual filings, a $350M haircut on the Verizon sale, a Russian-FSB indictment, a forfeited CEO bonus, and the SEC's first-ever breach-disclosure penalty
- RECORD
- The SEC's $35M order against Altaba is the one adjudication here — a settled administrative finding on disclosure. The FSB attribution is a DOJ indictment allegation, not a conviction. ATTRIBUTED
- STATUS
- RECORD STILL STANDS — ~3 billion accounts remains the largest disclosed breach; Altaba wound itself down; the indicted FSB officers remain at large
This one is a company, not a person — and a company that spoke, when it finally spoke, through a single CEO. Keep the two distinct; this file does. There are also two breaches here, easy to blur: a 2013 intrusion that eventually counted every account Yahoo ever made, and a separate 2014 intrusion of half a billion. Only the second is the one the Justice Department indicted.
The interesting part was never the hacking. Everyone gets hacked. The interesting part is the silence — and what the silence cost once the buyer, the regulator, and the Senate all wanted the same question answered. Every beat below carries its receipt. Both sides get the microphone. You decide.
the drama timeline
ACT I — THE BREACHES (2013–2014)
Two intrusions, a year apart, of different scale and different authorship. Note which one the company learns about fast, and which one it will spend years failing to count.
-
AUG 2013
The 2013 intrusion
Attackers compromise Yahoo user accounts in a breach the company will not disclose for three years, and will not size correctly for four. First announced in December 2016 as roughly one billion accounts, it is finally revised in October 2017 to all ~3 billion Yahoo accounts — every account the company had ever created, and the largest breach on public record.
-
LATE 2014
The 2014 intrusion — the “crown jewels”
In a separate intrusion, attackers take usernames, email addresses, phone numbers, birthdates, encrypted passwords, and security questions for ~500 million accounts. Per the SEC's later order, Yahoo's information-security team learns within days that Russian hackers had stolen what the team internally called the company's “crown jewels.” This is the breach the Justice Department will indict.
ACT II — THE SILENCE (2014–2016)
The company knows. The filings go out anyway. And in the same window, a second controversy about what Yahoo was doing with user mail spills into the press.
-
2014–2016
Two years of filings, no disclosure
Across the two years following the 2014 breach, Yahoo files multiple quarterly and annual reports that, per the SEC, failed to disclose the breach or its potential business and legal impact — the finding the Commission would later settle for $35 million. Its risk-factor disclosures warned of breaches only as a hypothetical, the SEC found, while a real one sat unreported.
-
2015–2016
The email-scanning report — and the CISO's exit
Reuters reports, in coverage later cited by Rep. Ted Lieu's office, that Yahoo built a program to scan incoming Yahoo Mail on behalf of a U.S. intelligence agency, and that CISO Alex Stamos departed in 2015 in the aftermath. Yahoo publicly characterized the Reuters report as “misleading.” A separate controversy from the breaches — and disputed — but part of the same season of questions about what Yahoo did and did not tell people.
A reported story, contested by the company. It sits here attributed and rebutted, not asserted — a receipt, not a verdict.
-
SEP 2016
Disclosure — during the Verizon deal
Yahoo publicly discloses the 2014 breach — roughly 500 million accounts — for the first time, as Verizon's $4.83 billion acquisition of its operating business is being finalized. In December 2016 it discloses the separate, larger 2013 breach. The timing is the whole story: the buyer found out at nearly the same moment as the public.
ACT III — THE RECKONING (2017)
Once it is out, the bills arrive in order: the buyer's discount, the CEO's forfeited pay, a federal indictment, an upward revision to the largest number in the field, and a subpoena to the Senate.
-
FEB 2017
Verizon cuts the price by $350M
Verizon renegotiates, knocking ~$350 million off the purchase price, to about $4.48 billion, and the two companies agree to share certain post-close breach liabilities. The breaches carried a literal, invoiced price.
-
MAR 1, 2017
Mayer forgoes her bonus
Mayer announces she will forgo her 2016 annual cash bonus and her annual equity grant, writing that as CEO she is responsible for the company's security and wants the bonus redistributed to employees. The company's general counsel, Ronald Bell, resigns without severance.
-
MAR 15, 2017
The FSB indictment
The Justice Department indicts four men over the 2014 breach: two officers of Russia's Federal Security Service (FSB) — Dmitry Dokuchaev and Igor Sushchin — whom it alleges “protected, directed, facilitated and paid” two criminal hackers, Alexsey Belan and Karim Baratov. These are charges, not convictions; the FSB officers remain outside U.S. custody. Baratov, arrested in Canada, later pleaded guilty.
The nation-state defense at its strongest: when the indictment names foreign intelligence officers, “we were outgunned” stops being an excuse and starts being the Justice Department's own theory of the case.
-
OCT–NOV 2017
3 billion — and the apology
Yahoo revises the 2013 breach to all ~3 billion accounts. Weeks later, subpoenaed, Mayer testifies before the Senate Commerce Committee, apologizes “to each and every one of our users,” and tells senators that “all companies, even the most-well-defended ones, could fall victim to these crimes.”
ACT IV — THE PENALTY (2018)
Prosecutors handled the hackers. The regulator turned to a different question entirely: not who broke in, but what investors were told about it.
-
APR 24, 2018
The SEC's first breach-disclosure fine
The SEC announces that Altaba, formerly Yahoo!, agrees to pay $35 million to settle charges it misled investors by failing to disclose the breach — the Commission's first-ever enforcement action against a public company for failing to disclose a cybersecurity breach. Altaba settled without admitting or denying the findings. The one adjudication in this file is about the silence, not the hack.
-
EPILOGUE
The number that stayed
Verizon folded Yahoo's operating business into Oath, later Verizon Media; Altaba dissolved and wound down. The indicted FSB officers remain at large. And ~3 billion — every account Yahoo ever made — is still the largest breach on the public record. The archive keeps the tape running.
both sides, on the record
The adjudicated failure: the SEC found — and Altaba settled for $35 million — that Yahoo misled investors by failing to disclose one of the world's largest breaches across two years of quarterly and annual filings. It was the SEC's first enforcement of its kind [1].
The scale: ultimately ~3 billion accounts from the 2013 intrusion — every account the company ever created — plus a separate ~500 million from 2014. Both are the company's own restated findings [5] [9].
The timing and the cost: disclosure landed as Verizon was closing its purchase, which then cut ~$350 million off the price; the CEO forfeited her bonus; the general counsel resigned [6] [7].
The attackers were a nation-state. This is not the company's spin — it is the Justice Department's own indictment: FSB officers alleged to have directed and paid the hackers behind the 2014 breach. Defending against a hostile intelligence service is a materially different problem than stopping a lone criminal [2] [4].
Cooperation and remediation: Yahoo reported the 2014 intrusion to law enforcement when it learned of it, per Mayer's testimony; the DOJ credited the company's assistance; Altaba settled the SEC matter and agreed to maintain disclosure controls going forward [3] [1]. Disclosure timing, the company would note, is genuinely complicated when an active criminal investigation is running in parallel.
Scope of the record: the SEC matter was settled without any admission or denial of the findings — it is not a fraud judgment. No personal enforcement action was brought against Marissa Mayer, and she voluntarily gave up her bonus and equity. The 2015 email-scanning report was a Reuters story the company called “misleading,” not an adjudicated fact [1] [7] [8].
YOU DECIDE
Scoped to the claims, never the company — and never the CEO. The claim “Yahoo could not have stopped this” has real support on the public record: the Justice Department itself charged FSB officers for the 2014 breach, and nation-state intrusion is a category apart. That defense stays on the page at full strength. The claim “Yahoo told investors what it knew, when it knew it” is the one the record contradicts — the SEC found otherwise and Altaba paid $35 million, the first fine of its kind, to settle it.
Weigh the costly signals. The breach itself cost the company a ~$350 million discount on its own sale, a CEO's bonus, and a place in history for the largest number in the field. The one thing that would have cost far less — telling investors in 2014 what the security team already knew — is the thing that didn't happen. Nation-states are hard to stop. A disclosure is not.
The archive does not judge. The archive merely keeps the tape running.
evidence locker
PRIMARY RECORD
SEC — “Altaba, Formerly Known as Yahoo!, Charged With Failing to Disclose Massive Cybersecurity Breach; Agrees To Pay $35 Million” (press release 2018-71, Apr 24 2018) ADJUDICATED — the $35M settlement, the “first-ever” characterization, the “crown jewels” finding, the two-year non-disclosure. Settled without admission or denial.
sec.gov/newsroom/press-releases/2018-71
U.S. Department of Justice — “U.S. Charges Russian FSB Officers and Their Criminal Conspirators for Hacking Yahoo and Millions of Email Accounts” (Mar 15 2017) ATTRIBUTED — the indictment: FSB officers Dokuchaev and Sushchin, hackers Belan and Baratov, the 2014 breach. Charges, not convictions.
justice.gov/opa/pr/us-charges-russian-fsb-officers-…
DISCLOSURE, DEAL & PRESS
The standard. Everything above is sourced to an SEC enforcement order, a federal indictment, the subject's own Senate testimony, the company's own breach disclosures, and named press reporting. Facts are stated as facts; the FSB attribution is stated as the Justice Department's indictment allegation, not as a conviction; the email-scanning beat is stated as a reported and company-disputed story, not as fact. The company (Yahoo/Altaba) is distinguished from its CEO, the settled SEC order is distinguished from an admission of wrongdoing, and the defense — the nation-state attribution, the cooperation, the forfeited bonus, the without-admission settlement — is presented at full strength. No motive is asserted, no personal wrongdoing by Marissa Mayer is alleged. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.