Classified Class Action Blog

  • All Topics
  • Contributors
  • About
  • Contact
  • Subscribe

Yahoo Enters $80 Million Securities Class Action Settlement After Data Breach

by J. Robert MacAneney

On March 2, Yahoo, Inc. (“Yahoo”) filed a proposed settlement in In re Yahoo Inc. Securities Litigation, which was filed in U.S. District Court in San Francisco. The $80 million proposed settlement relates to a securities class litigation stemming from Yahoo’s 2013 and 2014 data breaches. While many elements of the Yahoo securities class action may be factually unique, the settlement is a milestone because it is the first significant securities fraud settlement from a cybersecurity breach.

In January 2017, the first of several securities class action lawsuits was filed against Yahoo and certain of its directors and officers in the Northern District of California. Plaintiff shareholders alleged that defendants failed to disclose the two largest data breaches in U.S. history, in which hackers stole the records of 3 billion users in 2013, and compromised the accounts of 500 million users in 2014. They further alleged that defendants failed to disclose two additional massive data breaches in 2015 and 2016, which affected approximately 32 million Yahoo users and caused financial harm to investors.

It is also alleged that, throughout the class period, defendants continued to reassure the public that Yahoo had “physical, electronic, and procedural safeguards that comply with federal regulations to protect personal information about [its users],” that it would publicly disclose all security vulnerabilities within 90 days of discovery, and that its data security employed “best practices,” among other misrepresentations. Plaintiff shareholders alleged that defendants knew but failed to disclose that Yahoo was employing grossly outdated and substandard information security methods and technologies, which had resulted in two of the largest data security breaches in history.

The stipulation of settlement does not say how the settlement will be funded. It states only that Yahoo will “pay the settlement or cause it to be paid.” The stipulation of settlement expressly includes defendants’ insurers which is not unusual. A description of how the settlement is to be funded mentions providing the insurers with information, which strongly suggests that the D&O insurers are funding at least some portion of the settlement.

In the past, public companies have defeated plaintiffs’ efforts to seek recovery through securities class actions relating to cybersecurity risks and events. However, recent events suggest that may change. Yahoo’s proposed settlement comes on the heels of updated guidance on cybersecurity disclosure issued by the Securities and Exchange Commission (SEC) on February 21. The SEC guidance calls on public companies to be more forthcoming when disclosing cybersecurity risks. Together, the Yahoo proposed settlement and the new SEC guidelines may provide the groundwork that enables plaintiffs’ law firms to bring securities actions to pursue these claims.

Print Friendly, PDF & Email

« Previous Article

Third Circuit Ascertainability Requirement Puts the Squeeze on Orange Juice Purchasers

Next Article »

Out of Proportion: Court Denies Discovery Requests in Putative TCPA Class Action Due to Burden On Defendant

About J. Robert MacAneney

J. Robert MacAneney is a shareholder at Carlton Fields in New York City. Connect with Robert on LinkedIn.

Related Articles

  1. Data Breach Class Actions: 2015 Year in Review and 2016 Preview
  2. Lone Objector’s Class-Conflict Arguments Miss the Target
  3. Fall Data Breach Roundup and 2018 Preview: Supreme Court, OPM, Equifax and More!

Get Weekly Updates!

Send Me Updates!

2025 Class Action Survey – Now Available!

DOWNLOAD NOW
Carlton Fields Logo A blog focused on the latest class action developments and trends by the attorneys of Carlton Fields.

Search

Topics

Industries/Practices
  • Construction
  • Consumer Finance & Banking
  • Food & Beverage
  • Health Care
  • Insurance
  • Labor, Employment & ERISA
  • Manufacturing & Products
  • Pharmaceutical
  • Privacy & Technology
  • Securities
  • Telecommunications

Substantive/Procedural
  • Arbitration
  • CAFA
  • Certification
    • Adequacy
    • Ascertainability
    • Commonality
    • Numerosity
    • Predominance
    • Superiority
    • Typicality
  • Decertification
  • Settlements
  • Standing
  • Striking of Class Allegations

Courts/Jurisdiction
  • Federal District Courts
  • Federal Circuit Courts of Appeal
  • United States Supreme Court
  • State Courts

Monthly Archives

Recent Articles

  • Supreme Court Refuses to Decide Whether Damages Class Containing Both Injured and Uninjured Members Can Be Certified
  • Royal Canin v. Wullschleger: A Primer on Jurisdiction
  • Classified (Bi-)Monthly: A Roundup of Class Action Decisions From Federal Appellate Courts July and August 2024

Get Weekly Updates!

Carlton Fields

  • carltonfields.com
  • Practices
  • Industries
  • Class Action Survey

Related Industries/Practices

  • National Class Actions
  • National Trial Practice
  • Appellate & Trial Support
  • Our Class Action Experience

Classified®: The Class Action Blog

  • All Topics
  • Contributors
  • About
  • Contact

Copyright © 2025 · Carlton Fields · All Rights Reserved