Marissa MayerYahoo CEO Marissa Mayer.AP Photo/Eric Risberg, File
US regulators are reportedly investigating why it took Yahoo so long to disclose it was hacked.
According to a new report from The Wall Street Journal, The Securities and Exchange Commission (SEC) is examining whether the company should have told investors sooner about two huge data breaches.
Yahoo has faced pointed questions about exactly when it knew about a 2014 cyber attack it announced in September 2016 that exposed the email credentials of half a billion accounts.
Then in December, Yahoo said it had uncovered yet another massive cyber attack, saying data from more than 1 billion user accounts was compromised in August 2013.
The SEC issued requests for documents in December, as it probes whether the technology company's disclosures about the cyber attacks complied with civil securities laws, according to the WSJ.
In a November 2016 quarterly filing, Yahoo said that it was "cooperating with federal, state and foreign" agencies, including the SEC, that were seeking information and documents about a "security incident and related matters."
In the US, securities industry rules require companies to disclose cyber breaches to investors. Although the SEC has long-standing guidance on when publicly traded companies should report hacking incidents, companies that have experienced known breaches often omit those details in regulatory filings, according to a 2012 Reuters investigation.
In September 2016, Democratic U.S. Senator Mark Warner asked the SEC to investigate whether Yahoo and its senior executives fulfilled obligations to inform investors and the public about the 2014 hacking attack.
The disclosures from Yahoo about both breaches came after the company agreed to sell its main business to Verizon in July, triggering questions about whether the deal would still be viable and, if so, at what price. The deal is expected to close soon, according to The New York Post, and will see what's left of the business renamed as "Altaba."
Other agencies looking into the data breach include the Federal Trade Commission, the U.S. Attorney's Office in Manhattan and "a number of State Attorneys General," Yahoo said in the November filing.