Uber disclosed that attackers had stolen data on around 57 million riders and drivers in October 2016, and that the company had paid them $100,000 to delete the data and keep the breach quiet. New chief executive Dara Khosrowshahi said it should not have happened.
What happened
- The attackers accessed data stored on a cloud service using credentials found in a code repository.
- The data included names, email addresses, and phone numbers, plus the driving licence numbers of around 600,000 US drivers.
- Uber did not notify regulators or those affected for about a year, and its chief security officer was dismissed.
- Uber later paid $148m in a settlement with US states, and was fined by the UK ICO and the Dutch data protection authority.
Why it mattered
Concealing a breach turned a serious incident into a lasting scandal, and the former security chief was later convicted in the US in connection with the cover-up.
Lessons for organisations
Never store credentials in code repositories, use multi-factor authentication on cloud accounts, and meet breach notification duties promptly and honestly. Any payment to attackers should be handled with legal advice and never used to avoid disclosure.
Source: NPR
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.