Does buying a tech company make me responsible for security breaches that happened before I owned it?
Again, this turns largely on deal structure. In a share sale, the buyer acquires the corporation itself, including its legal history, so liability arising from a breach that occurred before closing — regulatory exposure, potential claims from affected individuals, contractual liability to business customers — generally comes along with the company, whether or not it was disclosed or even discovered before the sale closed. In an asset sale, that kind of liability more often stays with the selling entity, though the buyer can still face reputational fallout, and sometimes contractual obligations, if it continues serving the same customers and using the same systems.
This is exactly why breach history and cybersecurity practices belong in technology due diligence alongside financial and legal review: an undisclosed past breach that surfaces after closing can trigger notification obligations, regulatory scrutiny, or customer claims that a buyer never priced into the deal. Representations and warranties about past incidents, backed by indemnities for anything not disclosed, are the standard way purchase agreements allocate this risk.
Confirming whether the seller has had any actual or suspected breaches, and how they were handled, should be a specific line of inquiry, not an assumption based on a clean-looking public reputation.
Key takeaways
- Share sales generally carry breach-related liability forward with the corporation.
- Asset sales offer more separation, though reputational and contractual exposure can still follow.
- Undisclosed past breaches can trigger obligations or claims that surface only after closing.
- Use specific representations, warranties, and indemnities to allocate breach-related risk.