In In re Alphabet Securities Litigation, the State of Rhode Island, as lead plaintiff, filed a Rule10b-5 action against Google LLC, its holding company Alphabet, Inc., and certain executives, alleging that the defendants failed to timely disclose certain cybersecurity defects and vulnerabilities. The district court granted defendants’ motion to dismiss the complaint, but on appeal, a three-judge panel of the 9th Circuit reversed in part, holding that the complaint “plausibly alleged” that the decision to omit information about these cybersecurity vulnerabilities “significantly altered the total mix of information available for decision-making by a reasonable investor” and that scienter—intent to deceive, manipulate or defraud—was adequately alleged. Importantly, the Court held that the complaint contained a plausible allegation that Alphabet’s omission was materially misleading: its risk factor discussion of cybersecurity was framed in the hypothetical, while, it was alleged, the “hypothetical” events had in fact already come to fruition.  The case serves as a reminder of a couple of now-familiar themes: companies need to regularly review their risk factor disclosures, even when—or perhaps especially when—they are incorporating them by reference to ensure that they have been appropriately updated to reflect actual events that may have made the risks described as merely hypothetical no longer so. It’s also notable that this case represents the second recent instance of allegations of failure to disclose the discovery of a material cybersecurity “vulnerability”—in the absence of a cyberattack—with disclosure ultimately compelled by the publication of an article exposing the defects.  It’s another reminder that companies need to be vigilant for potential disclosure obligations about cybersecurity that might arise outside the context of cyberattacks and hacks—in the more-difficult-to-assess context of cybersecurity vulnerabilities.

Background

According to the opinion, which, at this stage, assumes the facts plausibly alleged in the complaint, in March 2018, Google discovered that there was a vulnerability in its Google+ social network that had, for three years, left private data of hundreds of thousands of users exposed to third-party developers. As described by the Court, Alphabet and Google, after being warned by their “legal and policy staff that disclosure of these issues would result in immediate regulatory and governmental scrutiny,…chose to conceal this discovery, made generic statements about how cybersecurity risks could affect their business, and stated that there had been no material changes to Alphabet’s risk factors since 2017.” The question before the Court was whether the complaint adequately alleged that, by omitting to disclose these security problems, the defendants made materially misleading statements in a Form 10-Q and did so with scienter.  

According to the Court, since its IPO in 2004, Google has touted the importance of security—user privacy and user trust—to its business. The Court noted that Alphabet’s CFO remarked in February 2018 that “security is ‘clearly what we’ve built Google on,’” and its Form 10-K warned of the damage that could result in the event of a cybersecurity breach or privacy violation.  In the Spring of 2018, a public scandal involving the improper harvesting by a research firm of user data from an unrelated company led to increased scrutiny of data security practices of large social media companies, including Congressional oversight hearings.  The Court also noted that Google had reaffirmed its commitment to comply with the GDPR (the European framework for regulating data privacy protections), which required prompt disclosure of personal data breaches not later than 72 hours after learning of the breach.

Around the same time, the Court said, internal Google investigators discovered a “software glitch in the Google+ social network that had existed since 2015 (referred to in the complaint as the ‘Three-Year Bug’),” that allowed third-party developers to access and collect some “users’ profile data even if those users had relied on Google’s privacy settings to designate such data as nonpublic. The exposed private profile data included email addresses, birth dates, gender, profile photos, places lived, occupations, and relationship status.”  Moreover, it was alleged, a record-keeping limitation prevented Google from reviewing more than the two most recent weeks of user data access, with the result that Google could not determine how many third parties had accessed the data. The investigation into the Three-Year Bug was alleged to have also turned up other vulnerabilities.  

As alleged in the complaint, in light of the discovery of these vulnerabilities, Google’s legal and policy staff prepared the “Privacy Bug Memo,” a memo warning that disclosure of these security issues “would likely trigger ‘immediate regulatory interest’” and put the spotlight on the defendants. As a result, the complaint alleged, key officers and directors, including some of the defendants, “chose a strategy of nondisclosure,” and Google’s CEO “approved a plan to conceal the existence of the Three-Year Bug and other security vulnerabilities.” In addition, the Google and Alphabet CEOs “approved a plan to shut down the Google+ consumer platform,” a platform with 395 million monthly active users.

Nevertheless, according to the Court, Alphabet’s Form 10-Q for the period ended March 31, 2018, incorporated the risk factor disclosures from its 2017 Form 10-K and did not update to disclose the Three-Year Bug or other security vulnerabilities that had been discovered, specifically stating that there were “no material changes to our risk factors since our Annual Report on Form 10-K for the year ended December 31, 2017.” Likewise, it was alleged, no disclosures of the vulnerabilities were made on the earnings call or in the subsequent 10-Q. The same omission continued, it was alleged, in various statements by Google, Alphabet and their employees regarding security and privacy until October 2018.

On October 8, 2018, the WSJ published a story exposing “Google’s discovery of Google+’s security vulnerabilities and its decision to conceal those vulnerabilities.”  According to the Court, when “the news broke, Google published a blog post acknowledging the ‘significant challenges’ regarding data security identified in the Wall Street Journal article.” Senators of both parties wrote letters demanding investigations or criticizing the company for withholding information. As recited by the Court from the complaint, “Alphabet’s share price fell $11.91 on October 8, $10.75 on October 9, and $53.01 on October 10.”


Posted by Cooley