Site navigation

ICO Fines Yahoo £250K

Brian Baglow

,

Ico Fines Yahoo Over 2014 Data Breach

Fine issued for the 2014 data breach which exposed data of over 500 million users.

In 2014 Yahoo was suffered a serious data breach which saw the personal information of around 500 million users exposed. This week, the Information Commissioners Office (ICO) issued the company with a £250,000 fine over the incident, citing violations of the 1998 Data Protection Act.

It may seem odd, but all things considered, this could be a more or less positive outcome for the company, since it failed to report the breach for almost two years. Under GDPR the company would have been required to report the breach in 72 hours, or face a fine of up to €20m or 4% of the company’s global turnover.

Since the breach, Yahoo was acquired by US telecoms giant Verison, then merged with AOL to form a new company called Oath (which among many other things, owns TechCrunch), so 4% of that could have been… considerably more. GDPR cannot be applied retrospectively, so there may actually have been sighs of relief within Oath when the fine was handed out.

The ICO investigation focused on approximately 515,000 affected UK accounts for which Yahoo UK Services Ltd was the data controller.

The investigation unearthed a ‘catalogue of failures’ finding that Yahoo UK Services had:

  • Failed to take appropriate technical and organisational measures to protect the data against exfiltration by unauthorised persons
  • Failed to take appropriate measures to ensure that its data processor — Yahoo! Inc — complied with the appropriate data protection standards
  • Failed to ensure appropriate monitoring was in place to protect the credentials of Yahoo! employees with access to Yahoo! customer data
  • the inadequacies discovered had been in place for “a long period of time without being discovered or addressed”

According to the ICO personal data compromised in the breach included names, email addresses, telephone numbers, dates of birth, hashed passwords, and encrypted or unencrypted security questions and answers.

It considered the breach to be a “serious contravention of Principle 7 of the Data Protection Act 1998” — which states that appropriate technical and organisational measures must be taken against unauthorised or unlawful processing of personal data.

ICO deputy commissioner of operations, James Dipple-Johnstone, said: “People expect that organisations will keep their personal data safe from malicious intruders who seek to exploit it. The failings our investigation identified are not what we expect from a company that had ample opportunity to implement appropriate measures, and potentially stop UK citizens’ data being compromised.”

“Under the GDPR and the new Data Protection Act 2018, individuals have stronger rights and more control and choice over their personal data. If organisations, especially well-resourced, experienced ones, do not properly safeguard their customers’ personal data, they may find customers taking their business elsewhere.”

Enterprise Data Planning in Financial Services event

An Oath spokesman told TechCrunch: the company does not comment directly on regulatory actions — but pointed to several developments since Yahoo was acquired, including the doubling in size of the global security organization; the creation in March of a cybersecurity advisory board; and the relaunch in April of an integrated bug bounty program.

Movers and shakers

Brian Baglow

Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data