Luxembourg — Yahoo’s UK unit was fined £250,000 by a British regulator for failing to keep the data of more than half a million users in the country safe from a cyber-attack in 2014.

Tuesday’s decision comes less than a week after the Irish privacy watchdog, which is the lead authority for Yahoo in Europe, ordered the company to make "specified and mandatory" changes in the wake of one of the "biggest data breaches in history".

The UK information commissioner’s office (ICO) said on Tuesday that the incident exposed the personal data of approximately 500-million international users of Yahoo’s services.

The revelation by Yahoo in 2016 that the personal information of about 500-million people was stolen in a 2014 attack on its accounts, was followed just a few months later by the news of a second major security breach that may have affected more than 1-billion user accounts.

"The failings our investigation identified are not what we expect from a company that had ample opportunity to implement appropriate measures, and potentially stop UK citizens’ data being compromised," James Dipple-Johnstone, deputy commissioner of operations at the ICO, said in a statement.

Verizon Communications bought Yahoo last year for about $4.5bn. The breaches threatened the deal, cost millions of dollars in legal fees, and spurred more than 40 lawsuits in the US