Yahoo ConnectID Lawsuit: Email Tracking Case Update
Privacy · Ad Tech · Lawsuit Pending

Yahoo ConnectID Lawsuit: How Hashed Email Tracking Works, and Where the Case Stands in 2026

Published August 17, 2026

A consolidated class action in Manhattan federal court challenges Yahoo ConnectID, an advertising identifier that is built from an email address instead of a browser cookie. The technology matters beyond this one case: an identifier derived from what you type into a sign-up form does not reset when you clear cookies, which is exactly why the ad industry built these systems as browsers closed off the old ones.

Yahoo logo — Yahoo ConnectID email-based advertising identifier class action in the Southern District of New York
Allegations Only · No Settlement Yet

This article describes a pending class action complaint. The plaintiffs' statements below are unproven allegations. Yahoo denies them, no court has found Yahoo liable, no class has been certified, and there is nothing to claim. This page is informational and is not legal advice.

What Is This About?

Six named plaintiffs are suing Yahoo Inc. and Yahoo Ad Tech LLC in the U.S. District Court for the Southern District of New York over Yahoo ConnectID, an advertising identifier that is keyed to a person's email address rather than to a browser cookie. The consolidated case is Baker v. Yahoo Inc., No. 1:25-cv-02797-DLC, before Judge Denise L. Cote. A second suit filed a week later, Caplan v. Yahoo Inc., No. 1:25-cv-02943, was folded into it by an order of April 15, 2025 and is now a member case rather than a separate action.

The case has not reached the merits. Yahoo moved to dismiss, the court denied that motion without prejudice in November 2025 and ordered the plaintiffs to plead more specifically, and the fight since then has been over whether the dispute belongs in court at all. This page explains the technology at the center of it and lays out the docket as it stands.

Status Pleading Stage — Arbitration Motion Pending motion to compel arbitration filed January 30, 2026 · fully briefed as of June 2026 · no ruling on the public docket as of its last retrieval
What's at Issue An email-based ad identifier ConnectID maps a hashed email address to a persistent ID used in real-time bidding · the complaint says it has identified more than 300 million people
Can I Claim? No — nothing to claim no settlement, no certified class, no claim form · this is a report on a pending case

How Yahoo ConnectID Works

Start with the mechanism, because most of the legal argument follows from it. ConnectID is what the ad industry calls a people-based or cookieless identifier. Yahoo introduced it in 2020, under the earlier name Verizon Media ConnectID, and built it on the company's Identity Graph — the internal structure that ties together the signals Yahoo holds about a given person, including IP addresses and device identifiers.

The input is an email address. When someone logs into or signs up for a participating website, app or connected TV service, that property can pass the address to Yahoo, which matches it to an existing ConnectID or creates a new one and returns it. Yahoo's own open-source integration library documents the step plainly: its getIds() function accepts a publisher's pixel ID plus an email that may be supplied either already hashed or raw, and the README states that if a raw email is provided, a SHA-256 hash of it "will be used for syncing and local storage." The same function accepts optional GDPR and US Privacy consent parameters. What comes back is a small object — an ID type mapped to a value — that the publisher can attach to its ad requests.

SHA-256 is a one-way function, so the address cannot be read back out of the hash. What it is not is a random value. The same address, normalized the same way, always produces the same hash, which is precisely what makes it useful as a matching key: two companies that have never exchanged a customer list can independently hash the same address and discover they are describing the same person. The Federal Trade Commission made that point directly in a July 2024 post on its Technology Blog, writing that hashing does not make data anonymous and that companies should not act or claim otherwise.

From there the identifier travels through the ordinary machinery of programmatic advertising. Publishers sell ad space through supply-side platforms; advertisers buy it through demand-side platforms; and in the milliseconds between a page loading and an ad appearing, a bid request describing the available impression is broadcast to bidders. If a ConnectID is attached to that request, every recipient of the request sees an identifier that points at a specific person rather than at an anonymous browser session. Yahoo operates on both sides of that exchange, as a supply-side platform and a demand-side platform.

Why a Hashed Email Outlives Your Cookie Settings

The privacy question here is not really about hashing. It is about where the identifier comes from.

A third-party cookie lives in browser storage. It is scoped to one browser on one device, it can be blocked by the browser, and deleting it destroys the link — the next visit looks like a new person. That is why browser-level controls worked as well as they did, and why Safari's and Firefox's restrictions on third-party cookies, along with Apple's app-tracking prompt on iOS, were meaningful changes rather than cosmetic ones.

An email-derived identifier is not stored by the browser in the same sense. It is recomputed from something the person supplies, so the chain of custody runs through the login form rather than through the cookie jar. Clear your cookies and site data, switch to a different browser, pick up a phone instead of a laptop — and the moment the same address is entered on a participating site, the same hash appears and can be matched to the same identifier. The identifier does not need to survive in your browser, because it can be regenerated on demand.

That property is not a side effect. It is the product. Email-based IDs were built and marketed across the industry as the answer to cookie deprecation, and they reach places cookies never did — connected TVs and apps, where there is no third-party cookie to set in the first place. Whether users understood that trade when they typed an address into a sign-up form is the question the litigation is actually about. If you want the underlying vocabulary, our glossary entry on the California Invasion of Privacy Act covers the wiretap statute most often used against tracking technology, and our explainer on what counts as personally identifiable information covers the identifiability question the FTC was addressing.

What the Complaints Allege

The operative pleading has been amended several times; the second amended complaint, filed in September 2025, is the version the court described in its November opinion. Its allegations, none of which have been tested, are these.

Each named plaintiff created an account with an email address at one or more of four websites that the complaint says use Yahoo's tracking technology: CBS Sports, US Magazine, Realtor.com and FanDuel. The complaint alleges that on login, Yahoo intercepted the email address and assigned or attributed the person to a ConnectID, and then used that identifier together with Yahoo's other advertising and analytics products to intercept the person's searches, the full-string URLs of pages they viewed, their IP addresses and their device identifiers — and to build a profile keyed to the identifier. The complaint alleges the plaintiffs never consented to any of it.

The earlier Caplan complaint, now consolidated in, framed the technology claim in more detail: that ConnectID was designed specifically as a workaround to cookie deprecation, that it is stored in the user's local storage and associated with a first-party cookie, that it is transmitted in OpenRTB bid requests, and that Yahoo matches it against identifiers held by other data companies to enrich the resulting profiles. It also alleged that Yahoo's privacy policy did not mention ConnectID while representing that email addresses are not shared with partners — the deception theory at the heart of the consumer-protection count.

The two proposed nationwide classes are an "identifier class" of everyone in the United States for whom Yahoo intercepted or assigned a ConnectID or other identifier, and a "communications class" of everyone in the United States whose communications with third parties Yahoo intercepted or used without consent. The second amended complaint pleads nine counts: New York General Business Law § 349; common-law intrusion upon seclusion; invasion of privacy under the California Constitution; three counts under the California Invasion of Privacy Act (Penal Code §§ 631, 632, and 638.50 and 638.51); the California Comprehensive Computer Data Access and Fraud Act, Penal Code § 502; unjust enrichment; and a count seeking injunctive relief. Four of the six named plaintiffs live in California, one in New York and one in Vermont.

What Yahoo Says

Yahoo denies the claims and has not answered the complaint on the merits. Its central argument on the motion to dismiss was consent: that each plaintiff agreed to the practices described in the complaint when they signed up for CBS Sports, Realtor.com, US Magazine or FanDuel, and that their agreement to the policies referenced on those sign-up pages is fatal to every count. To make that argument at the pleading stage, Yahoo asked the court to take judicial notice of the relevant sign-up interfaces and policies.

The court did not reject that theory. It described consent as "a threshold issue in this litigation that is appropriately considered prior to Yahoo's other arguments for dismissal," and said it would likely be appropriate to take judicial notice of the sign-up pages and policies the plaintiffs actually encountered, which "could be dispositive of the plaintiffs' claims."

Outside the courtroom, Yahoo markets ConnectID as a privacy-forward product: an identity solution built on authenticated, consented signals, aligned with industry self-regulatory frameworks, that auto-detects common privacy signals on a page and does not generate an identifier for users who have opted out. Its developer documentation carries GDPR and US Privacy parameters to that end, and the company publishes a public opt-out portal, which describes the practice as serving ads and linking information using "cryptographic de-identified hashes of email addresses and/or phone numbers" — a reminder that the input is not only an email address. The plaintiffs' case is essentially that those representations do not match what the technology does; the court has not decided who is right.

Where the Case Stands

The docket is the reliable record here, and it shows a case that has spent well over a year on threshold questions without reaching the substance of the privacy claims.


No ruling on the arbitration motion appears on the public docket as of its last retrieval, and the docket entries visible through free public sources lag PACER. Treat "no ruling shown" as the limit of what the record establishes, not as confirmation that nothing has happened since.

The arbitration motion is the development to watch, and its significance is procedural rather than substantive. Nothing about it speaks to whether ConnectID violates any privacy statute. What it decides is the forum: a court weighing claims on behalf of a proposed nationwide class, or individual arbitrations under the terms of service of whichever accounts the plaintiffs signed up for. In privacy litigation against large platforms that question frequently determines the shape of everything that follows.

What This Means for You

Practically, nothing to do. There is no settlement, no certified class and no claim form, and there may never be one — most privacy class actions end well short of a payout. Anyone telling you to sign up for a payment from this case is describing something that does not exist.

What is worth taking from it is the technical point, which applies well beyond Yahoo. Clearing cookies and using a privacy-focused browser still do useful work against cookie-based tracking, but they do not reach an identifier derived from an email address you typed into a sign-up form. The controls that do bite on email-based IDs are different ones: using address aliases or a relay service so different sites see different addresses, declining to create accounts you do not need, and using the opt-outs the identity vendors publish. Yahoo runs a public opt-out portal covering both email addresses and phone numbers, and it works without a Yahoo account — our step-by-step guide to opting out of ConnectID walks through it, including the verification click that people routinely miss and the reason a single submission only covers one address. None of that is a comment on the merits of this case; it is just where the mechanism actually is.

If you want to see how these theories fare once a case survives the pleading stage, the same statutes are behind several settlements OCA tracks, including the Forbes website-tracking settlement for California readers and the Flo period-tracker app settlement, both of which have open claim windows. Yahoo's earlier data breach settlement is a separate matter and unrelated to ConnectID.

Questions

Is there anything to claim in the Yahoo ConnectID case?

No. There is no settlement, no certified class and no claim form. The case is still at the pleading stage: a motion to compel arbitration was filed on January 30, 2026 and was fully briefed as of June 2026, with no ruling shown on the public docket as of the last retrieval. Nothing on this page is a claim process, and no court has found Yahoo liable.

Does clearing cookies remove a ConnectID?

Not in the way clearing cookies removes a cookie-based ad ID. ConnectID is derived from an email address rather than from browser storage, so the same address produces the same hash and can be matched to the same identifier the next time it is entered on a participating site. Yahoo's developer documentation describes hashing a raw email with SHA-256 for syncing and local storage. Clearing browser data can remove a locally cached copy, but it does not change the underlying email-to-identifier mapping.

What is the difference between ConnectID and a third-party cookie?

A third-party cookie is stored by the browser, is scoped to a single browser on a single device, and can be blocked or deleted. An email-based identifier is computed from something the user types in, so it is stable across browsers, devices and sessions, and it can work in places cookies never reached, such as connected TV apps. That durability is the reason ad tech firms built email-based IDs as cookies were restricted, and it is also the core of what the plaintiffs are challenging.

Does hashing an email address make it anonymous?

The Federal Trade Commission has said it does not. In a July 2024 Technology Blog post the FTC wrote that hashing does not render data anonymous, because a hash that always returns the same value for the same input still functions as a persistent identifier for that person. A hash conceals the literal characters of an address while preserving its usefulness as a matching key between companies.

What is Yahoo's position in the case?

Yahoo denies the claims. Its primary argument on the motion to dismiss was that the plaintiffs consented to the practices described in the complaint when they signed up for the third-party websites at issue, and it asked the court to take judicial notice of the sign-up pages and policies in effect. The court called consent a threshold issue in the litigation. Separately, Yahoo publicly describes ConnectID as a consent-based identity product that honors GDPR and US Privacy signals and offers an opt-out.

Can I opt out of ConnectID?

Yes. Yahoo runs a public opt-out portal that accepts an email address, a phone number, or both, and it does not require a Yahoo account. Submitting the form is not the end of it: Yahoo sends a confirmation message with a verification link to prove you control the address or number, and the opt-out is not complete until that link is followed. It covers only the identifier you submitted, so each address and number needs its own submission. An opt-out is a forward-looking control rather than a deletion request, and it is separate from this lawsuit — using it neither joins nor waives anything in the case.

Sources

Docket — Baker v. Yahoo Inc., No. 1:25-cv-02797 (S.D.N.Y.)
Docket — Caplan v. Yahoo Inc., No. 1:25-cv-02943 (S.D.N.Y.)
• Opinion and Order, Baker v. Yahoo Inc., No. 25cv2797 (DLC), Dkt. 62 (S.D.N.Y. Nov. 19, 2025), and the accompanying scheduling order at Dkt. 63
• Class Action Complaint, Caplan v. Yahoo Inc., No. 1:25-cv-02943, Dkt. 1 (S.D.N.Y. Apr. 9, 2025)
Yahoo ConnectID integration library and documentation (Yahoo)
Yahoo ConnectID opt-out page
FTC Technology Blog — "No, hashing still doesn't make your data anonymous" (July 2024)


For more class actions keep scrolling below.
Status Pending — motion to compel arbitration fully briefed no certified class · no settlement · discovery was stayed pending the dismissal motion
Case Title Baker v. Yahoo Inc. & Yahoo Ad Tech LLC Caplan v. Yahoo Inc. consolidated into this action April 15, 2025
Case Number 1:25-cv-02797-DLC (member case 1:25-cv-02943)
Court U.S. District Court, Southern District of New York
Judge Denise L. Cote
Date Filed April 3, 2025 the consolidated member case was filed April 9, 2025

More on Privacy & Tracking Cases