In 2014, Yahoo suffered a breach that exposed 500 million personal accounts including personally identifiable information. They failed to discover or disclose this breach for two years.
Over the past decade, hundreds of millions of user accounts have been compromised, and in many cases, personal data been leaked.
In some cases the exploits have been new, and the attacked providers followed best practices. But, in other cases, these companies were negligent, dishonest in their security claims, or failed to disclose the breaches promptly.
The breached companies are often treated like victims in these cases, but in truth, the victims are the users.
When breaches result from negligence, or are not promptly disclosed by providers, these companies should be held responsible.



