Login Register
Follow Us

Hackers stole data from 5.7 cr Uber riders, drivers

SAN FRANCISCO: Uber has said that hackers compromised personal data from some 57 million (5.7 crore) riders and drivers in a breach kept hidden for a year.

Show comments

San Francisco, November 22

Uber has said that hackers compromised personal data from some 57 million (5.7 crore) riders and drivers in a breach kept hidden for a year.

“None of this should have happened, and I will not make excuses for it,” said a statement from chief executive Dara Khosrowshahi, who took over at the ridesharing giant in August.

Two members of the Uber information security team who “led the response” that included not alerting users that their data was breached were let go from the San Francisco-based company effective yesterday, according to Khosrowshahi.

The Uber chief said he only recently learned that outsiders had broken into a cloud-based server used by the company for data and downloaded a “significant” amount of information.

Stolen files included names, email addresses, and mobile phone numbers for riders, and the names and driver licence information of some 600,000 drivers, according to Uber.

Uber paid the hackers $100,000 to destroy the data, not telling riders or drivers whose information was at risk, according to a source familiar with the situation.

Co-founder and ousted chief Travis Kalanick was advised of the breach shortly after it was discovered, but it was not made public until Uber’s new boss Khosrowshahi learned of the incident.

“You may be asking why we are just talking about this now, a year later,” Khosrowshahi said. “I had the same question, so I immediately asked for a thorough investigation of what happened and how we handled it.”

Khosrowshahi said what he learned about Uber’s failure to notify users or regulators prompted corrective actions.

“All companies would be wise to remember this: cock-ups are bad, but cover-ups can kill you,” computer security specialist Graham Cluley said in a blog post.

“You can ask forgiveness for being hacked, but many people will find it harder to forgive and forget if you deliberately concealed the truth from them.”

Yahoo and Equifax were hit with criticism for how long it took the companies to disclose hacks.

“Breach disclosure is taking too long,” said McAfee vice-president of labs Vincent Weafer, who described Uber’s decision to pay the hackers off as unusual, and questioned whether it was wise.

Uber is notifying drivers whose licence numbers were swiped, and offering them credit and identity theft protections. The company also said it is notifying regulators, and monitoring affected rider accounts for signs of fraud. “While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes,” Khosrowshahi said. — AFP

Show comments
Show comments

Top News

View All

'I am woman now': UP man claims sex change operation without his consent, case filed

The man was operated on only after the two psychiatrists deemed him mentally fit

Polluted air killed 1.69 lakh Indian kids in 2021

Highest under-5 fatalities in country: SoGA report

Bengaluru couple shocked as they find snake in Amazon package

Snake is suspected to be a spectacled cobra (Naja Naja), a highly venomous snake species indigenous to Karnataka

100 off 27 balls: Pinjore-born Sahil Chauhan scripts new T20 record in Cyprus

His unbeaten innings of 144 off 41 deliveries was studded with six boundaries and 18 sixes

Most Read In 24 Hours