Yahoo Fined £250,000 Over Cyber-attack
Yahoo's UK arm has been fined £250,000 ($335,000) by the UK Information Commissioner's Office (ICO) over a data breach affecting more than 500 million users which took place in 2014.
The incident was reported two years later.
The firm said "state-sponsored" hackers had stolen personal information, which included names, emails, unencrypted security questions and answers.
The ICO said Yahoo had failed to take appropriate measures to protect it.
Yahoo said it did not comment on regulatory action.
"The failings our investigation identified are not what we expect or will accept from a company processing significant volumes of personal data," wrote deputy commissioner of operations James Dipple-Johnstone in a blog.
"Yahoo! UK Services Ltd had ample opportunity to implement appropriate measures, and potentially stop UK citizens' data being compromised."
Around eight million of the affected accounts were believed to belong to people in the UK.
The ICO's investigation also found:
- The firm failed to ensure that its Yahoo-owned data processor "complied with the appropriate data protection standards"
- It did not ensure that the credentials of employees with access to customer data were monitored
- There was "a long period of time" before the flaws which led to the breach were discovered or addressed
Verizon acquired Yahoo in 2017 and combined it with AOL to form a company called Oath.
The firm was investigated under the UK 1988 Data Protection Act which pre-dates the new European data regulation GDPR.
Tony Pepper, CEO of Egress Software Technologies, said the data breach would go down in history as "one of the most notorious" - both because of its size and the two-year period between the attack and the report.
"Although the fine has been a long time coming, I imagine there would be some sighs of relief that the investigation was carried out under the Data Protection Act, rather than the GDPR which has much tougher consequences for a breach," he said.
From Chip War To Cloud War: The Next Frontier In Global Tech Competition
The global chip war, characterized by intense competition among nations and corporations for supremacy in semiconductor ... Read more
The High Stakes Of Tech Regulation: Security Risks And Market Dynamics
The influence of tech giants in the global economy continues to grow, raising crucial questions about how to balance sec... Read more
The Tyranny Of Instagram Interiors: Why It's Time To Break Free From Algorithm-Driven Aesthetics
Instagram has become a dominant force in shaping interior design trends, offering a seemingly endless stream of inspirat... Read more
The Data Crunch In AI: Strategies For Sustainability
Exploring solutions to the imminent exhaustion of internet data for AI training.As the artificial intelligence (AI) indu... Read more
Google Abandons Four-Year Effort To Remove Cookies From Chrome Browser
After four years of dedicated effort, Google has decided to abandon its plan to remove third-party cookies from its Chro... Read more
LinkedIn Embraces AI And Gamification To Drive User Engagement And Revenue
In an effort to tackle slowing revenue growth and enhance user engagement, LinkedIn is turning to artificial intelligenc... Read more