← All enforcement actions
SEC DisclosureSecurities ActB2C Tech

Altaba (Yahoo)$35M SEC + $117.5M class SOX fine (2018)

First SEC enforcement against a public company for failing to disclose a cyber breach

Penalty
$35M SEC + $117.5M class
Regulator
US SEC + class action
Jurisdiction
United States
Records affected
3B

What happened

Yahoo experienced a 2014 breach affecting 500M (later revised to 3B) accounts but did not disclose it until late 2016. The SEC fined Yahoo $35M for misleading investors via securities filings that omitted the known breach, and a class action settled for $117.5M.

Root cause

What every team should do

  1. Cyber incidents need a documented materiality-assessment path into Disclosure Committee
  2. SEC Cybersecurity Rule (Dec 2023): material incidents disclosed within 4 business days on Form 8-K Item 1.05
  3. Annual Form 10-K Reg S-K Item 106 — disclose cyber risk management + governance
Source: SEC press release (Apr 24, 2018).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which SOX controls you are missing — mapped to enforcement patterns like this one.

Run my SOX audit Generate missing policies

Related enforcement actions

Meta Platforms
€1.2B
Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework
TikTok
€345M
Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations
Meta / Instagram
€405M
Children's business-account email + phone exposed publicly