Case file · YAHOO 2014

The Yahoo breach of 2014: 500 million accounts and 2 years of silence

Published 2026-09-29 · 4 min read · Missing control: Escalate and disclose breaches promptly

Within days of the December 2014 intrusion that exposed about 500 million user accounts, Yahoo's own security team knew what had happened, and investors did not find out for more than 2 years.[1][2] This case file covers how the break-in worked, how the silence turned into a $35 million penalty, and the one control that was missing.

What happened

In late 2014, intruders copied Yahoo's user database, which held names, recovery email addresses, phone numbers and other account details.[2] The data taken also included birthdates, scrambled passwords and security questions and answers.[1] They also got hold of an internal account management tool that could be used to change user accounts.[2]

According to U.S. prosecutors, the intrusion was directed by 2 officers of Russia's FSB intelligence service, who worked with a criminal hacker and paid another to break into email accounts at other providers.[2] The access lasted until September 2016, and stolen information was used through December 2016.[2]

Inside Yahoo, the information security team learned of the breach within days in December 2014 and reported it to senior management and the legal department, the SEC later found.[1] But Yahoo did not tell investors. It disclosed the breach only in 2016, while Verizon was in the middle of buying its operating business, a deal that closed in June 2017.[1]

How they got in

Prosecutors said the intruders first stole copies of the user database in November and December 2014.[2] With that data and the account management tool, they did not need anyone's password. Instead, they were able to create the small digital tokens, known as cookies, that websites use to remember that a person is already logged in. With a forged cookie, an account simply opened.[2]

The targets were not random. Prosecutors said more than 6,500 accounts were accessed directly, including those of Russian journalists, U.S. and Russian government officials, employees of security companies, and staff at banks, financial firms, airlines and transportation companies.[2] Separately, more than 30 million accounts were misused for spam.[2]

What it cost

On March 15, 2017, the Justice Department charged the 2 FSB officers and 2 hackers in a 47-count indictment, with charges including economic espionage, computer fraud and wire fraud.[2]

The bigger bill came from the silence. On April 24, 2018, the Securities and Exchange Commission announced that Altaba, the company left over after the Verizon sale, would pay a $35 million penalty.[1] Yahoo, it said, failed to properly investigate, did not share what it knew with its auditors or outside lawyers, left the breach out of its quarterly and annual reports for 2 years, and lacked procedures for deciding when a cyber incident must be disclosed.[1] The SEC's enforcement co-director said the agency does not second-guess good-faith judgment calls, but that this response was so lacking that action was clearly warranted.[1]

The missing control

The missing control: a process to escalate and disclose breaches promptly. Yahoo's security staff did their part and spotted the theft quickly, but there was no working path to turn that knowledge into decisions, investigation and disclosure.[1]

A clear incident rule would have required the breach to go straight to the people who decide what to tell auditors, regulators, investors and users, with a deadline for doing so. That would not have undone the theft. It would have prompted password resets and warnings years earlier, cut short the time the stolen data stayed useful, and avoided the $35 million penalty for keeping quiet.[1]

What to do in your business

Watch the case
Yahoo knew within days and waited two yearsDrops 2027-01-02
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. SEC: Altaba, formerly known as Yahoo, charged with failing to disclose massive cybersecurity breach; agrees to pay $35 million
  2. U.S. Department of Justice: U.S. charges Russian FSB officers and their criminal conspirators for hacking Yahoo and millions of email accounts