Uber Paid Hackers $100k to Hide Attack that Exposed Data of 57 Million Users

According to a new report from Bloomberg, Uber suffered a massive data breach last year that exposed the personal data of 57 million customers and drivers.

The attack occurred in October 2016 and included the personal information of 50 million riders and 7 million drivers. Personal information of drivers included about 600,000 U.S. driver’s license numbers.

Uber said that social security numbers, credit card details, trip location and other sensitive information was not stolen in the hack.

The pair of hackers reportedly accessed a private GitHub repository that was used by Uber’s software engineers. By accessing the code base, the hackers were able to get credentials to access the company’s Amazon Web Services account and obtain an archive of user data.

Uber was obligated to inform authorities of the breach, and alert drivers whose license information was stolen, but the company instead chose to pay $100,000 to delete the data. In a statement, Uber CEO Dara Khosrowshahi said:

“At the time of the incident, we took immediate steps to secure the data and shut down further unauthorized access by the individuals. We also implemented security measures to restrict access to and strengthen controls on our cloud-based storage accounts.”

Uber’s efforts to conceal the hack were led by chief security officer Joe Sullivan, who has since been ousted from the company. Uber also let go of Craig Clark, a senior lawyer who worked with Sullivan.

Matt Olsen, a former member of the general counsel at the National Security Agency, has been hired to help the company restructure its security teams.

Want to see more of our stories on Google?

Add iPhone in Canada as a Preferred Source on Google

P.S. Want to keep this site truly independent? Support us by buying us a beer, treating us to a coffee, or shopping through Amazon here. Links in this post are affiliate links, so we earn a tiny commission at no charge to you. Thanks for supporting independent Canadian media!

Subscribe
Notify of
guest
6 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Joe
Joe
8 years ago

Whoa, that sounds like a pretty huge scandal to me. They were obligated to inform authorities of the breach, but instead they paid hackers $100K to conceal it?

Olley
Olley
Reply to  Joe
8 years ago

Conceal
Don’t feel
Put on a show
Make one wrong move
And everyone will know…

My 1/2 cents
My 1/2 cents
Reply to  Olley
8 years ago

But only a few really “care”.

Joe
Joe
Reply to  My 1/2 cents
8 years ago

LOL Yeah I’m so busy being upset about net neutrality, it’s hard to be upset about this today too. Watching the news is such a horror show these days. When’s the next iPhone coming out?

sukisszoze
sukisszoze
8 years ago

Only $100k..must have taken by the hackers pretty easily..lol

My 1/2 cents
My 1/2 cents
8 years ago

Uber is a mess…just like Trump. Yet people support both #sigh

6
0
Would love your thoughts, please comment.x
()
x