SEC joins the list of agencies probing giant Yahoo breach

By
Follow google news

Did the company wait too long to warn investors?

The US Securities and Exchange Commission is investigating a previously disclosed data breach at Yahoo, the company has confirmed in a formal filing.

SEC joins the list of agencies probing giant Yahoo breach

Yahoo said in a November 2016 quarterly notice it was “cooperating with federal, state and foreign” agencies, including the SEC, that were seeking information and documents about a "security incident and related matters".

The SEC is investigating whether two massive data breaches at Yahoo should have been reported sooner to investors.

An SEC spokesman declined to comment. A Yahoo spokesman directed Reuters to the company's November filing.

Yahoo has faced pointed questions about exactly when it knew about the 2014 cyber attack it announced in September, that exposed the email credentials of half a billion accounts.

In December, Yahoo said it had uncovered yet another massive cyber attack, saying data from more than 1 billion user accounts was compromised in August 2013.

The SEC issued requests for documents in December, as it probes whether the technology company’s disclosures about the cyber attacks complied with civil securities laws, according to the Wall Street Journal.

Securities industry rules require companies to disclose cyber breaches to investors. Although the SEC has long-standing guidance on when publicly traded companies should report hacking incidents, companies that have experienced known breaches often omit those details in regulatory filings, according to a 2012 Reuters investigation.

Democratic US Senator Mark Warner asked the SEC in September to investigate whether Yahoo and its senior executives fulfilled obligations to inform investors and the public about the 2014 hacking attack.

The disclosures from Yahoo about both breaches came after the company agreed to sell its main business to Verizon in July, triggering questions about whether the deal would still be viable and, if so, at what price.

Other agencies looking into the data breach include the Federal Trade Commission, the US Attorney’s Office in Manhattan and “a number of State Attorneys General,” Yahoo said in the November filing.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Supply chain attack hits 100 million-download Axios npm package

Supply chain attack hits 100 million-download Axios npm package

NAB is co-designing a SIEM with Databricks

NAB is co-designing a SIEM with Databricks

APRA pulls data submission system after security pentest

APRA pulls data submission system after security pentest

Councils push for federal shared security centre funding

Councils push for federal shared security centre funding

Log In

  |  Forgot your password?