Don’t do SECURITY. Do business SECURELY.

Uber reveals it concealed 2016 breach and paid hackers $100,000

Uber admitted that a 2016 breach exposed data on 57 million people and that it paid the attackers to delete the data and stay quiet.

Uber disclosed that attackers had stolen data on around 57 million riders and drivers in October 2016, and that the company had paid them $100,000 to delete the data and keep the breach quiet. New chief executive Dara Khosrowshahi said it should not have happened.

What happened

  • The attackers accessed data stored on a cloud service using credentials found in a code repository.
  • The data included names, email addresses, and phone numbers, plus the driving licence numbers of around 600,000 US drivers.
  • Uber did not notify regulators or those affected for about a year, and its chief security officer was dismissed.
  • Uber later paid $148m in a settlement with US states, and was fined by the UK ICO and the Dutch data protection authority.

Why it mattered

Concealing a breach turned a serious incident into a lasting scandal, and the former security chief was later convicted in the US in connection with the cover-up.

Lessons for organisations

Never store credentials in code repositories, use multi-factor authentication on cloud accounts, and meet breach notification duties promptly and honestly. Any payment to attackers should be handled with legal advice and never used to avoid disclosure.

Source: NPR

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights