Uber concealed cyber attack that exposed 57 million people's data

We’re sorry, this feature is currently unavailable. We’re working to restore it. Please try again later.

Advertisement

This was published 6 years ago

Uber concealed cyber attack that exposed 57 million people's data

By Eric Newcomer
Updated

Hackers stole the personal data of 57 million customers and drivers from Uber, a massive breach that the company concealed for more than a year.

This week, the ride-hailing company ousted Joe Sullivan, chief security officer, and one of his deputies for their roles in keeping the hack under wraps.

Compromised data from the attack on October 2016 included names, email addresses and phone numbers of 50 million Uber riders around the world, the company told Bloomberg on Tuesday.

The personal information of about 7 million drivers was accessed as well, including about 600,000 US driver's licence numbers.

"None of this should have happened, and I will not make excuses for it": Uber CEO Dara Khosrowshahi.

"None of this should have happened, and I will not make excuses for it": Uber CEO Dara Khosrowshahi.Credit: AP

No Social Security numbers, credit card details, trip location info or other data were taken, Uber said.

At the time, Uber was negotiating with US regulators investigating separate claims of privacy violations.

Uber now says it had a legal obligation to report the hack to regulators and to drivers whose licence numbers were taken.

Instead, the company paid hackers $US100,000 ($132,000) to delete the data and keep the breach quiet.

Advertisement
Uber's co-founder and former chief executive Travis Kalanick.

Uber's co-founder and former chief executive Travis Kalanick.Credit: AP

Uber said it believed the information was never used but declined to disclose the identities of the attackers.

"None of this should have happened, and I will not make excuses for it," Dara Khosrowshahi, who took over as chief executive officer in September, said in an emailed statement. "We are changing the way we do business."

Uber paid hackers $US100,000 to delete the data and keep the breach quiet.

Uber paid hackers $US100,000 to delete the data and keep the breach quiet. Credit: Bloomberg

Hackers have successfully infiltrated numerous companies in recent years. The Uber breach, while large, is dwarfed by those at Yahoo, MySpace, Target, Anthem and Equifax. What's more alarming are the extreme measures Uber took to hide the attack.

The breach is the latest explosive scandal Khosrowshahi inherited from his predecessor, Travis Kalanick.

Hackers stole the data of 57 million Uber customers and drivers around the world.

Hackers stole the data of 57 million Uber customers and drivers around the world. Credit: AP

Kalanick, Uber's co-founder and former chief executive, learnt of the hack in November 2016, the company said.

Uber had just settled a lawsuit with the New York attorney-general over data security disclosures and was in the process of negotiating with the Federal Trade Commission (FTC) over the handling of consumer data.

Uber ousted Joe Sullivan, chief security officer, and one of his deputies for their roles in keeping the hack under wraps.

Uber ousted Joe Sullivan, chief security officer, and one of his deputies for their roles in keeping the hack under wraps.

Kalanick declined to comment on the hack.

Sullivan spearheaded the response to the hack last year, a spokesman told Bloomberg.

Sullivan, a one-time federal prosecutor who joined Uber in 2015 from Facebook, has been at the centre of much of the decision-making that has come back to bite Uber this year.

Bloomberg reported last month that the board commissioned an investigation into the activities of Sullivan's security team. This project, conducted by an outside law firm, discovered the hack and the ensuing cover-up, Uber said.

Here's how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, the company said.

A patchwork of state and federal laws require companies to alert people and government agencies when sensitive data breaches occur. Uber said it was obliged to report the hack of driver's licence information but failed to do so.

"At the time of the incident, we took immediate steps to secure the data and shut down further unauthorised access by the individuals," Khosrowshahi said.

"We also implemented security measures to restrict access to, and strengthen controls on, our cloud-based storage accounts."

Uber has earned a reputation for flouting regulations in areas where it has operated since its founding in 2009.

The US has opened at least five criminal probes into possible bribes, illicit software, questionable pricing schemes and theft of a competitor's intellectual property, people familiar with the matters have said.

The company also faces dozens of civil suits.

London and various governments have taken steps towards banning the service, citing what they say is reckless behaviour by Uber.

In January 2016, the New York attorney-general fined Uber $US20,000 for failing to promptly disclose an earlier data breach in 2014.

After last year's cyber attack, the company was negotiating with the FTC on a privacy settlement even as it haggled with the hackers on containing the breach, Uber said.

The company finally agreed to the FTC settlement three months ago, without admitting wrongdoing and before telling the agency about last year's attack.

The new chief executive said his goal was to change Uber's ways.

Uber said it informed New York's attorney-general and the FTC about the October 2016 hack for the first time on Tuesday.

Khosrowshahi asked for the resignation of Sullivan and fired Craig Clark, a senior lawyer who reported to Sullivan. The men did not respond to requests for comment.

The company said its investigation found that Salle Yoo, the outgoing chief legal officer who has been scrutinised for her responses to other matters, hadn't been told about the incident.

Her replacement, Tony West, will start at Uber on Wednesday and has been briefed on the cyber attack.

Kalanick was ousted as chief executive in June under pressure from investors, who said he put the company at legal risk. He remains on the board and recently filled two seats he controlled.

"While I can't erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes," Khosrowshahi said in the emailed statement.

Uber said it had hired Matt Olsen, a former general counsel at the National Security Agency and director of the National Counterterrorism Centre, as an adviser. He will help the company restructure its security teams. Uber hired Mandiant, a cybersecurity firm owned by FireEye, to investigate the hack.

Loading

The company plans to release a statement to customers saying it has seen "no evidence of fraud or misuse tied to the incident." Uber said it will provide drivers whose licences were compromised with free credit protection monitoring and identity theft protection.

The Washington Post

Most Viewed in Technology

Loading