Los Angeles Times

Yahoo to pay $50 million to victims of giant data breach

- ASSOCIATED PRESS

Yahoo has agreed to pay $50 million in damages and provide two years of creditmoni­toring services to 200 million people whose email addresses and other personal informatio­n were stolen as part of the biggest security breach in history.

The restitutio­n hinges on federal court approval of a settlement filed late Monday in a 2-year-old lawsuit seeking to hold Yahoo accountabl­e for digital burglaries that occurred in 2013 and 2014 but weren’t disclosed until 2016.

It adds to the financial fallout from a security lapse that provided a mortifying end to Yahoo’s existence as an independen­t company and to then-Chief Executive Marissa Mayer’s six-year reign.

Yahoo revealed the problem after it had already negotiated a $4.83-billion deal to sell its digital services to Verizon Communicat­ions. It then had to discount that price by $350 million to reflect its tarnished brand and the specter of other potential costs stemming from the breach.

Hackers, including some the FBI linked to Russia, hit about 3 billion Yahoo accounts. The settlement reached in a San Francisco court covers about 1 billion of those accounts, held by about 200 million people in the United States and Israel from 2012 through 2016.

Claims for a portion of the $50-million fund can be submitted by any eligible Yahoo account holder who suffered losses resulting from the security breach. The costs can include such things as identity theft, delayed tax refunds or other problems linked to having had personal informatio­n pilfered during the Yahoo break-ins.

Under the preliminar­y settlement, the fund would compensate Yahoo account holders at a rate of $25 an hour for time spent dealing with issues triggered by the security breach. Those with documented losses could ask for up to 15 hours of lost time, or $375. Those who can’t document losses could file claims seeking up to five hours, or $125, for time spent dealing with the breach. Account holders who paid $20 to $50 annually for a premium email account would be eligible for a 25% refund.

The free credit-monitoring service from AllClear could end up being the most valuable part of the settlement for most account holders. The lawyers representi­ng the account holders pegged the retail value of AllClear’s credit-monitoring service at $14.95 a month, or about $359 for two years — but Yahoo probably will not pay that rate. The settlement didn’t disclose how much Yahoo had agreed to pay AllClear for covering affected account holders.

The lawyers for Yahoo’s account holders called the deal a positive outcome, given the uncertaint­y of what might have happened had the case headed to trial.

Estimates of damages caused by security breaches vary widely, with experts asserting the value of personal informatio­n held in email accounts can range from $1 to $8 per account. Those figures suggest Yahoo could have faced a bill of more than $1 billion had it lost the case.

Yahoo disputed those damages estimates and noted that many of its account holders submitted false birth dates and other informatio­n when they set up their email.

Oath, the Verizon subsidiary that oversees Yahoo, didn’t respond to requests for comment Tuesday.

A hearing to approve the preliminar­y settlement is scheduled for Nov. 29 before U.S. District Judge Lucy Koh in San Jose. If approved, notices will be emailed to affected account holders and published in People and National Geographic magazines.

Newspapers in English

Newspapers from United States