Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

What Does SEC’s Yahoo Settlement Mean for Cyber Enforcement?

Author: Scarinci Hollenbeck, LLC

Date: May 23, 2018

Key Contacts

Back

The SEC Recently Announced it has Reached a $35 Million Settlement with Altaba Inc. (formerly known as Yahoo! Inc.) – What Does this Settlement Mean for Cyber Enforcement?

The Securities and Exchange Commission (SEC) recently announced that it has reached a $35 million settlement with Altaba Inc. (formerly known as Yahoo! Inc.). The settlement resolves allegations that the company misled investors by failing to timely report its massive 2014 data breach.

What does Yahoo Settlement Mean for Cyber Enforcement?
Photo courtesy of Daniel Falcão (Unsplash.com)

The SEC enforcement action is the first to crack down on a public company over inadequate data breach disclosures, but it is unlikely to be the last. “We do not second-guess good faith exercises of judgment about cyber-incident disclosure.  But we have also cautioned that a company’s response to such an event could be so lacking that an enforcement action would be warranted.  This is clearly such a case,” Steven Peikin, Co-Director of the SEC Enforcement Division, said in a press statement.

Yahoo’s 2014 Data Breach

In December 2014, Yahoo’s information security team discovered that Russian hackers had stolen what they internally called the company’s “crown jewels.” It included usernames, email addresses, phone numbers, birthdates, encrypted passwords, and security questions and answers for hundreds of millions of user accounts.

Although the breach was reported to members of Yahoo’s senior management and legal department, Yahoo did not publicly disclose the breach until more than two years later in 2016, when the company was in the process of closing the acquisition of its operating business by Verizon Communications, Inc. The disclosure of the data breach lowered the value of the company in its acquisition by Verizon Communications, Inc. After Yahoo disclosed the 2014 data breach, Verizon renegotiated the stock purchase agreement to reduce the price paid for Yahoo’s operating business by $350 million, representing a 7.25 percent reduction in price. The fallout from the company’s mismanagement of the breach also resulted in the resignation of the company’s top lawyer. 

SEC’s Allegations

In its subsequent enforcement action, the SEC alleged that Yahoo failed to properly investigate the circumstances of the breach and to adequately consider whether the breach needed to be disclosed to investors. The SEC’s order specifically determined that when Yahoo filed several quarterly and annual reports during the two-year period following the breach, the company failed to disclose the breach or its potential business impact and legal implications. Instead, the company’s SEC filings stated that it faced only the risk of, and negative effects that might flow from, data breaches.  

According to the SEC, Yahoo’s disclosure violations continued in connection with a proposed sale of its operating business to Verizon in July 2016. Although Yahoo was aware of additional evidence in the first half of 2016 indicating that its user database had been stolen, Yahoo made affirmative representations denying the existence of any significant data breaches in a July 23, 2016 stock purchase agreement with Verizon, by which Verizon was to acquire Yahoo’s operating business for $4.825 billion.

The SEC’s order also concluded that Yahoo did not share information regarding the breach with its auditors or outside counsel in order to assess the company’s disclosure obligations in its public filings. Finally, the SEC’s order finds that Yahoo failed to maintain disclosure controls and procedures designed to ensure that reports from Yahoo’s information security team concerning cyber breaches, or the risk of such breaches, were properly and timely assessed for potential disclosure.

Yahoo neither admitted nor denied the findings in the SEC’s order. However, it will pay $35 million to resolve the allegations.

SEC Cyber Guidance

Earlier this year, SEC published interpretive guidance to help public companies in preparing disclosures about cybersecurity risks and incidents. As discussed in greater detail in a prior article, the SEC guidance emphasized the importance of cybersecurity policies and procedures and the application of disclosure controls and procedures, insider trading prohibitions, and Regulation FD and selective disclosure prohibitions in the context of cybersecurity.

With regard to disclosure obligations, the SEC advises that a company is required to disclose “such further material information, if any, as may be necessary to make the required statements, in light of the circumstances under which they are made, not misleading.” The guidance advises that the SEC considers omitted information to be material if there is a substantial likelihood that a reasonable investor would consider the information important in making an investment decision or that disclosure of the omitted information would have been viewed by the reasonable investor as having significantly altered the total mix of information available.

As highlighted by the SEC, the materiality of cybersecurity risks or incidents depends upon their nature, extent, and potential magnitude, particularly as they relate to any compromised information or the business and scope of company operations. The range of harm, such as reputational harm, financial performance, and a likelihood of litigation, also influences the materiality of cybersecurity risks and incidents also depends on the range of harm that such incidents could cause.

Key Takeaway for Public Companies

The SEC will continue to scrutinize how public companies respond to data breaches and other cyber incidents. We encourage businesses to thoroughly review their cyber policies and procedures to verify that they are equipped to quickly and thoroughly respond to a breach before it occurs.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
Zoning Laws Explained: What You Need to Know Before Buying Property post image

Zoning Laws Explained: What You Need to Know Before Buying Property

Before buying property, it is critical to determine whether local zoning laws may affect your plans. If you plan to redevelop the property, you will want to confirm that local zoning regulations permit development as intended. If acquiring property that is already developed, you must verify that the use is permitted in the underlying zoning […]

Author: Wendy Rubinstein Quiroga

Link to post with title - "Zoning Laws Explained: What You Need to Know Before Buying Property"
Special Needs Trusts in New Jersey: Planning for Your Loved One’s Future post image

Special Needs Trusts in New Jersey: Planning for Your Loved One’s Future

For parents of a child with a disability, estate planning raises concerns that go well beyond deciding who will inherit their assets. Parents may spend years making sure their child has the right care, services, and support. Eventually, they must also confront a difficult question: Who will take over when they can no longer do […]

Author: George McGowan

Link to post with title - "Special Needs Trusts in New Jersey: Planning for Your Loved One’s Future"
What Every Real Estate Investor Should Know Before Buying a Rental Property post image

What Every Real Estate Investor Should Know Before Buying a Rental Property

Before buying a New Jersey rental property, an investor should verify realistic operating numbers, the property’s legal and regulatory status, lead-based paint and flood compliance, the existing leases and tenant protections, and the right ownership structure. A rental property is more than a piece of real estate; it is an operating business subject to legal, […]

Author: Donald M. Pepe

Link to post with title - "What Every Real Estate Investor Should Know Before Buying a Rental Property"
Can You Change an Irrevocable Trust in New Jersey? post image

Can You Change an Irrevocable Trust in New Jersey?

In New Jersey, an irrevocable trust can sometimes be modified even though its name suggests otherwise, and one of the primary tools for doing so is a process called decanting. Whether decanting is available depends on the specific terms of the trust and the discretion given to the trustee. Key takeaways: New Jersey has no […]

Author: Marc J. Comer

Link to post with title - "Can You Change an Irrevocable Trust in New Jersey?"
How Intellectual Property Valuation Will Impact Business Transactions post image

How Intellectual Property Valuation Will Impact Business Transactions

Intellectual property valuation determines the monetary value of a business’s IP assets, and it drives outcomes in licensing deals, joint ventures, mergers and acquisitions, financing, and ownership disputes. The most valuable assets of a business are often the things that cannot be seen or touched: a proprietary process, a copyrighted work, brand recognition, or the […]

Author: Jay McDaniel

Link to post with title - "How Intellectual Property Valuation Will Impact Business Transactions"
Data Center, Dark Fiber, and Lit Services Agreements in New Jersey: Key Terms and Legal Pitfalls post image

Data Center, Dark Fiber, and Lit Services Agreements in New Jersey: Key Terms and Legal Pitfalls

For New Jersey data center owners and operators, a service agreement may look routine when it is signed. The network is functioning, the vendor is meeting its installation schedule, and the parties have agreed on pricing and performance specifications. The provisions that seem most important at that stage are often the technical ones. That changes […]

Author: George McGowan

Link to post with title - "Data Center, Dark Fiber, and Lit Services Agreements in New Jersey: Key Terms and Legal Pitfalls"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
“If you would like to submit a file, please email it directly to info@sh-law.com.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!