Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Uber hid a 2016 data breach that affected 57 million people

The ride-hail company has fired two people who were in charge of handling the response to this hack.

Uber logo on a mobile phone in front of the Uber sign
Uber logo on a mobile phone in front of the Uber sign
studioEAST / Getty

Uber failed to notify some 57 million users that their data — including names, email addresses, phone numbers and driver’s license numbers — was exposed when hackers accessed that information in 2016, newly minted CEO Dara Khosrowshahi said in a statement on Tuesday.

As a result of the failure to notify its customers, Khosrowshahi opened an investigation into how the company handled the incident and fired two people who handled the response process.

Joe Sullivan, Uber’s chief security officer, was one of them. He was hired in 2015 as Uber’s first security chief after the company had suffered a series of hacks. The attack that occurred under Sullivan’s watch is likely the largest data breach the embattled ride-hailing giant has experienced.

Bloomberg News first reported the hack. Instead of notifying users, Uber paid the hackers $100,000 to delete the data they got ahold of and keep the hack quiet.

“None of this should have happened, and I will not make excuses for it,” Khosrowshahi wrote in a statement. “While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes. We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers.”

The company has now recruited the help of Matt Olsen, a former NSA general counsel and the co-founder of a cybersecurity consulting firm called IronNet Cybersecurity, to guide its security team going forward.

Have more information or any tips? Johana Bhuiyan is the senior transportation editor at Recode and can be reached at johana@recode.net or on Signal, Confide, WeChat or Telegram at 516-233-8877. You can also find her on Twitter at @JmBooyah.

In his statement, Khosrowshahi said the 600,000 drivers whose license numbers were downloaded will receive free credit monitoring and identity theft protection, and will be individually notified. However, if drivers want to proactively check the status of their account, they can look here.

He also said the company has notified authorities. So far, the office of New York Attorney General Eric Schneiderman has opened an investigation into the breach.

Uber says it does not believe riders need to take any further action but should monitor their credit and other accounts.

He also said that forensic experts had not found any sign that data on trip location history, credit card numbers, bank account numbers, birthdate or social security numbers were downloaded.

Khosrowshahi wrote that the company doesn’t believe that any of the data that was accessed has been misused, but is monitoring the affected accounts.

The company is already facing a number of federal probes into its privacy practices as it transitions from its former chief legal officer, Salle Yoo, who was not notified about this incident, to Tony West, who will start this week.

Update: This post was updated to include that the New York attorney general’s office is investigating the breach.


This article originally appeared on Recode.net.

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh