Yahoo offers $117.5m settlement for 2013 monster hack

This revised proposition translates to just four cents apiece across all three billion compromised accounts

Yahoo

Yahoo has offered a settlement nearing 100 million to victims whose personal details were stolen by hackers in the world's largest data breach.

The web giant has proposed a $117.5 million (89.9 million) class-action settlement as recompense to the victims of a massive hack in 2013 that saw attackers steal account details and unencrypted security information.

But the offer will only cover a portion of the three billion victims, approximately 896 million accounts and no more than 194 million individuals in the US and Isreal, according to documents filed this week.

This roughly translates to less than 60 cents per class action member, and if the settlement were to be spread across all three billion compromised accounts, just four cents each.

But the full payout also includes lawyers fees of up to $30 million, $6 million in administrative costs, and costs and expenses of no more than $2.5 million. The named plaintiffs representing all 896 accounts will then be able to individually claim up to $7,500 as compensation.

Meanwhile, the individual members of the class action will have to settle for either two years of credit monitoring, estimated at $24 million collectively, or a fixed $100 figure for those who've already undergone credit monitoring. Small business and paid account users, meanwhile, could receive a payout of $500.

Yahoo previously offered a settlement last October, which Judge Lucy Koh struck down in January because it was not deemed "fair, reasonable and adequate" as required by law.

This was also due to the high share of lawyers fees, $35 million, and confusion over how much victims may recover from the proposed package. The revised settlement offer must also gain Koh's approval before any payouts can begin.

As part of the settlement, US telecoms giant Verizon, which owns Yahoo, has also offered to spend $306 million over the next four years on information security. This includes $108 million for 2019, and at least $66 million per year until 2022.

The parent company has also committed to more than quadruple Yahoo's staffing in this area to 200 through to 2022, against staffing levels at 'legacy Yahoo'.

Yahoo sustained three significant data breaches between 2013 and 2016, the largest of which is the subject of this lawsuit and saw personal information taken from all three billion compromised accounts.

CEO of web security firm High-Tech Bridge Ilia Kolochenko branded the $117.5 million sum "embarrassingly modest" given the scale and severity of the incident.

"It's pretty widespread for class actions that usually enrich the attorneys, not the victims," he said. "Otherwise, the settlement conveys an illusory message of relatively modest penalties for negligent data protection.

"In 2019, even a less severe breach is capable of exposing your company to incomparably severe and harsh sanctions in different jurisdictions. We have to take cybersecurity seriously or pay a considerable price."

The Information Commissioner's Office (ICO) previously fined Yahoo's UK branch 250,000 for failing to secure the personal information of 515,000 British users during a separate hack that took place in 2014.

IT Pro has contacted Verizon Media for a statement.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

Biden nominees highlight tough cyber security challenges
cyber security

Biden nominees highlight tough cyber security challenges

20 Jan 2021
Report: Security staff excluded from app development
cyber security

Report: Security staff excluded from app development

20 Jan 2021
Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

20 Jan 2021
SolarWinds hackers hit Malwarebytes through Microsoft exploit
hacking

SolarWinds hackers hit Malwarebytes through Microsoft exploit

20 Jan 2021

Most Popular

Citrix buys Slack competitor Wrike in record $2.25bn deal
collaboration

Citrix buys Slack competitor Wrike in record $2.25bn deal

19 Jan 2021
IT retailer faces €10.4m GDPR fine for employee surveillance
General Data Protection Regulation (GDPR)

IT retailer faces €10.4m GDPR fine for employee surveillance

18 Jan 2021
How to recover deleted emails in Gmail
email delivery

How to recover deleted emails in Gmail

6 Jan 2021