▼
Allegations Only · No Settlement Yet
This article describes a pending class action complaint. The plaintiffs' statements below are
unproven allegations. Yahoo denies them, no court has found Yahoo liable, no class has been
certified, and there is nothing to claim. This page is informational and is not legal advice.
Six named plaintiffs are suing Yahoo Inc. and Yahoo Ad Tech LLC in the U.S. District Court for the Southern
District of New York over Yahoo ConnectID, an advertising identifier that is keyed to a person's email
address rather than to a browser cookie. The consolidated case is Baker v. Yahoo Inc.,
No. 1:25-cv-02797-DLC, before Judge Denise L. Cote. A second suit filed a week later,
Caplan v. Yahoo Inc., No. 1:25-cv-02943, was folded into it by an order of April 15, 2025 and is
now a member case rather than a separate action.
The case has not reached the merits. Yahoo moved to dismiss, the court denied that motion without
prejudice in November 2025 and ordered the plaintiffs to plead more specifically, and the fight since then
has been over whether the dispute belongs in court at all. This page explains the technology at the center
of it and lays out the docket as it stands.
Status
Pleading Stage — Arbitration Motion Pending
motion to compel arbitration filed January 30, 2026 · fully briefed as of June 2026 · no ruling on the public docket as of its last retrieval
What's at Issue
An email-based ad identifier
ConnectID maps a hashed email address to a persistent ID used in real-time bidding · the complaint says it has identified more than 300 million people
Can I Claim?
No — nothing to claim
no settlement, no certified class, no claim form · this is a report on a pending case
Start with the mechanism, because most of the legal argument follows from it. ConnectID is what the ad
industry calls a people-based or cookieless identifier. Yahoo introduced it in 2020, under the earlier name
Verizon Media ConnectID, and built it on the company's Identity Graph — the internal structure that ties
together the signals Yahoo holds about a given person, including IP addresses and device identifiers.
The input is an email address. When someone logs into or signs up for a participating website, app or
connected TV service, that property can pass the address to Yahoo, which matches it to an existing
ConnectID or creates a new one and returns it. Yahoo's own open-source integration library documents the
step plainly: its getIds() function accepts a publisher's pixel ID
plus an email that may be supplied either already hashed or raw, and the README states that if a raw email
is provided, a SHA-256 hash of it "will be used for syncing and local storage." The same function accepts
optional GDPR and US Privacy consent parameters. What comes back is a small object — an ID type mapped to a
value — that the publisher can attach to its ad requests.
SHA-256 is a one-way function, so the address cannot be read back out of the hash. What it is not is a
random value. The same address, normalized the same way, always produces the same hash, which is precisely
what makes it useful as a matching key: two companies that have never exchanged a customer list can
independently hash the same address and discover they are describing the same person. The Federal Trade
Commission made that point directly in a July 2024 post on its Technology Blog, writing that hashing does
not make data anonymous and that companies should not act or claim otherwise.
From there the identifier travels through the ordinary machinery of programmatic advertising. Publishers
sell ad space through supply-side platforms; advertisers buy it through demand-side platforms; and in the
milliseconds between a page loading and an ad appearing, a bid request describing the available impression
is broadcast to bidders. If a ConnectID is attached to that request, every recipient of the request sees an
identifier that points at a specific person rather than at an anonymous browser session. Yahoo operates on
both sides of that exchange, as a supply-side platform and a demand-side platform.
The privacy question here is not really about hashing. It is about where the identifier comes from.
A third-party cookie lives in browser storage. It is scoped to one browser on one device, it can be blocked
by the browser, and deleting it destroys the link — the next visit looks like a new person. That is why
browser-level controls worked as well as they did, and why Safari's and Firefox's restrictions on
third-party cookies, along with Apple's app-tracking prompt on iOS, were meaningful changes rather than
cosmetic ones.
An email-derived identifier is not stored by the browser in the same sense. It is recomputed from something
the person supplies, so the chain of custody runs through the login form rather than through the cookie
jar. Clear your cookies and site data, switch to a different browser, pick up a phone instead of a laptop —
and the moment the same address is entered on a participating site, the same hash appears and can be
matched to the same identifier. The identifier does not need to survive in your browser, because it can be
regenerated on demand.
That property is not a side effect. It is the product. Email-based IDs were built and marketed across the
industry as the answer to cookie deprecation, and they reach places cookies never did — connected TVs and
apps, where there is no third-party cookie to set in the first place. Whether users understood that trade
when they typed an address into a sign-up form is the question the litigation is actually about. If you
want the underlying vocabulary, our glossary entry on the
California
Invasion of Privacy Act covers the wiretap statute most often used against tracking technology, and our
explainer on what counts as personally identifiable
information covers the identifiability question the FTC was addressing.
The operative pleading has been amended several times; the second amended complaint, filed in September
2025, is the version the court described in its November opinion. Its allegations, none of which have been
tested, are these.
Each named plaintiff created an account with an email address at one or more of four websites that the
complaint says use Yahoo's tracking technology: CBS Sports, US Magazine, Realtor.com and FanDuel. The
complaint alleges that on login, Yahoo intercepted the email address and assigned or attributed the person
to a ConnectID, and then used that identifier together with Yahoo's other advertising and analytics
products to intercept the person's searches, the full-string URLs of pages they viewed, their IP addresses
and their device identifiers — and to build a profile keyed to the identifier. The complaint alleges the
plaintiffs never consented to any of it.
The earlier Caplan complaint, now consolidated in, framed the technology claim in more detail: that
ConnectID was designed specifically as a workaround to cookie deprecation, that it is stored in the user's
local storage and associated with a first-party cookie, that it is transmitted in OpenRTB bid requests, and
that Yahoo matches it against identifiers held by other data companies to enrich the resulting profiles. It
also alleged that Yahoo's privacy policy did not mention ConnectID while representing that email addresses
are not shared with partners — the deception theory at the heart of the consumer-protection count.
The two proposed nationwide classes are an "identifier class" of everyone in the United States for whom
Yahoo intercepted or assigned a ConnectID or other identifier, and a "communications class" of everyone in
the United States whose communications with third parties Yahoo intercepted or used without consent. The
second amended complaint pleads nine counts: New York General Business Law § 349; common-law intrusion upon
seclusion; invasion of privacy under the California Constitution; three counts under the California
Invasion of Privacy Act (Penal Code §§ 631, 632, and 638.50 and 638.51); the California Comprehensive
Computer Data Access and Fraud Act, Penal Code § 502; unjust enrichment; and a count seeking injunctive
relief. Four of the six named plaintiffs live in California, one in New York and one in Vermont.
Yahoo denies the claims and has not answered the complaint on the merits. Its central argument on the
motion to dismiss was consent: that each plaintiff agreed to the practices described in the complaint when
they signed up for CBS Sports, Realtor.com, US Magazine or FanDuel, and that their agreement to the
policies referenced on those sign-up pages is fatal to every count. To make that argument at the pleading
stage, Yahoo asked the court to take judicial notice of the relevant sign-up interfaces and policies.
The court did not reject that theory. It described consent as "a threshold issue in this litigation that is
appropriately considered prior to Yahoo's other arguments for dismissal," and said it would likely be
appropriate to take judicial notice of the sign-up pages and policies the plaintiffs actually encountered,
which "could be dispositive of the plaintiffs' claims."
Outside the courtroom, Yahoo markets ConnectID as a privacy-forward product: an identity solution built on
authenticated, consented signals, aligned with industry self-regulatory frameworks, that auto-detects
common privacy signals on a page and does not generate an identifier for users who have opted out. Its
developer documentation carries GDPR and US Privacy parameters to that end, and the company publishes a
public opt-out portal, which describes the practice as serving ads and linking information using
"cryptographic de-identified hashes of email addresses and/or phone numbers" — a reminder that the input is
not only an email address. The plaintiffs' case is essentially that those representations do not match what
the technology does; the court has not decided who is right.
The docket is the reliable record here, and it shows a case that has spent well over a year on threshold
questions without reaching the substance of the privacy claims.
-
April 3 and 9, 2025
Two putative class actions are filed in the Southern District of New York over
ConnectID. The second, Caplan v. Yahoo Inc., is filed as related to the first.
-
April 15, 2025
Judge Cote consolidates the actions under docket number 25cv2797 and stays
Yahoo's deadline to respond until a consolidated complaint is filed. Interim lead class counsel is
appointed the following week, with a consolidated complaint due in June.
-
June 24, 2025
The court sets a dismissal-briefing schedule and stays discovery until the
motion to dismiss is resolved.
-
August–September 2025
Yahoo moves to dismiss on August 4. The plaintiffs respond by amending
instead, and the second amended complaint — now naming Yahoo Ad Tech LLC as well — moots that
motion. Yahoo files a renewed motion to dismiss on September 26, with a request for judicial notice
of twenty-five policy versions and ten sign-up pages.
-
November 19, 2025
The court denies the motion to dismiss and the judicial-notice request
without prejudice to renewal. This is not a merits ruling: the court found the complaint too vague
to litigate consent, because it never said when the plaintiffs created their accounts, which left
Yahoo unable to identify which sign-up pages and policies applied. Acting on its own initiative
under Rule 12(e), the court ordered a more definite statement.
-
December 3, 2025
The plaintiffs file a further amended pleading supplying the account-creation
details the court demanded.
-
January 30, 2026
Rather than a renewed Rule 12(b)(6) motion, the docket shows a motion to
compel arbitration and to stay the case, with a supporting memorandum and declarations. If granted,
it would move the claims out of federal court and out of the class format.
-
March 9, 2026
A stipulated protective order governing confidential material is entered.
-
May–June 2026
Oppositions to the arbitration motion are filed in early May and replies on
June 2, portions under seal; the court grants the sealing requests on June 3. The motion is fully
briefed and awaiting decision.
No ruling on the arbitration motion appears on the public docket as of its last retrieval, and the docket
entries visible through free public sources lag PACER. Treat "no ruling shown" as the limit of what the
record establishes, not as confirmation that nothing has happened since.
The arbitration motion is the development to watch, and its significance is procedural rather than
substantive. Nothing about it speaks to whether ConnectID violates any privacy statute. What it decides is
the forum: a court weighing claims on behalf of a proposed nationwide class, or individual arbitrations
under the terms of service of whichever accounts the plaintiffs signed up for. In privacy litigation
against large platforms that question frequently determines the shape of everything that follows.
Practically, nothing to do. There is no settlement, no certified class and no claim form, and there may
never be one — most privacy class actions end well short of a payout. Anyone telling you to sign up for a
payment from this case is describing something that does not exist.
What is worth taking from it is the technical point, which applies well beyond Yahoo. Clearing cookies and
using a privacy-focused browser still do useful work against cookie-based tracking, but they do not reach
an identifier derived from an email address you typed into a sign-up form. The controls that do bite on
email-based IDs are different ones: using address aliases or a relay service so different sites see
different addresses, declining to create accounts you do not need, and using the opt-outs the identity
vendors publish. Yahoo runs a public opt-out portal covering both email addresses and phone numbers, and it
works without a Yahoo account — our
step-by-step guide to opting
out of ConnectID walks through it, including the verification click that people routinely miss and the
reason a single submission only covers one address. None of that is a comment on the merits of this case;
it is just where the mechanism actually is.
If you want to see how these theories fare once a case survives the pleading stage, the same statutes are
behind several settlements OCA tracks, including the
Forbes
website-tracking settlement for California readers and the
Flo period-tracker
app settlement, both of which have open claim windows. Yahoo's earlier
data breach settlement is a
separate matter and unrelated to ConnectID.
Is there anything to claim in the Yahoo ConnectID case?
No. There is no settlement, no certified class and no claim form. The case is still at the pleading
stage: a motion to compel arbitration was filed on January 30, 2026 and was fully briefed as of
June 2026, with no ruling shown on the public docket as of the last retrieval. Nothing on this page
is a claim process, and no court has found Yahoo liable.
Does clearing cookies remove a ConnectID?
Not in the way clearing cookies removes a cookie-based ad ID. ConnectID is derived from an email
address rather than from browser storage, so the same address produces the same hash and can be
matched to the same identifier the next time it is entered on a participating site. Yahoo's
developer documentation describes hashing a raw email with SHA-256 for syncing and local storage.
Clearing browser data can remove a locally cached copy, but it does not change the underlying
email-to-identifier mapping.
What is the difference between ConnectID and a third-party cookie?
A third-party cookie is stored by the browser, is scoped to a single browser on a single device, and
can be blocked or deleted. An email-based identifier is computed from something the user types in,
so it is stable across browsers, devices and sessions, and it can work in places cookies never
reached, such as connected TV apps. That durability is the reason ad tech firms built email-based
IDs as cookies were restricted, and it is also the core of what the plaintiffs are challenging.
Does hashing an email address make it anonymous?
The Federal Trade Commission has said it does not. In a July 2024 Technology Blog post the FTC wrote
that hashing does not render data anonymous, because a hash that always returns the same value for
the same input still functions as a persistent identifier for that person. A hash conceals the
literal characters of an address while preserving its usefulness as a matching key between
companies.
What is Yahoo's position in the case?
Yahoo denies the claims. Its primary argument on the motion to dismiss was that the plaintiffs
consented to the practices described in the complaint when they signed up for the third-party
websites at issue, and it asked the court to take judicial notice of the sign-up pages and policies
in effect. The court called consent a threshold issue in the litigation. Separately, Yahoo publicly
describes ConnectID as a consent-based identity product that honors GDPR and US Privacy signals and
offers an opt-out.
Can I opt out of ConnectID?
Yes. Yahoo runs a public opt-out portal that accepts an email address, a phone number, or both, and
it does not require a Yahoo account. Submitting the form is not the end of it: Yahoo sends a
confirmation message with a verification link to prove you control the address or number, and the
opt-out is not complete until that link is followed. It covers only the identifier you submitted,
so each address and number needs its own submission. An opt-out is a forward-looking control rather
than a deletion request, and it is separate from this lawsuit — using it neither joins nor waives
anything in the case.
• Docket — Baker v. Yahoo Inc., No. 1:25-cv-02797 (S.D.N.Y.)
• Docket — Caplan v. Yahoo Inc., No. 1:25-cv-02943 (S.D.N.Y.)
• Opinion and Order, Baker v. Yahoo Inc., No. 25cv2797 (DLC), Dkt. 62 (S.D.N.Y. Nov. 19, 2025), and the accompanying scheduling order at Dkt. 63
• Class Action Complaint, Caplan v. Yahoo Inc., No. 1:25-cv-02943, Dkt. 1 (S.D.N.Y. Apr. 9, 2025)
• Yahoo ConnectID integration library and documentation (Yahoo)
• Yahoo ConnectID opt-out page
• FTC Technology Blog — "No, hashing still doesn't make your data anonymous" (July 2024)
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
For more class actions keep scrolling below.
Status
Pending — motion to compel arbitration fully briefed
no certified class · no settlement · discovery was stayed pending the dismissal motion
Case Title
Baker v. Yahoo Inc. & Yahoo Ad Tech LLC
Caplan v. Yahoo Inc. consolidated into this action April 15, 2025
Case Number
1:25-cv-02797-DLC (member case 1:25-cv-02943)
Court
U.S. District Court, Southern District of New York
Judge
Denise L. Cote
Date Filed
April 3, 2025
the consolidated member case was filed April 9, 2025