Uber confesses it covered up a huge data breach

A picture of the Uber app in a car
(Image credit: Uber)

Uber has admitted it covered up a major data breach in 2016 that led to user data being leaked online.

The US Department of Justice (DoJ) said in a press release the taxi company, “admits that its personnel failed to report the November 2016 data breach to the Federal Trade Commission despite a pending FTC investigation into data security at the company.” 

Uber's confession came as part of a settlement which will see it avoid criminal prosecution from the DoJ.

Hush money

The hack, which happened in October 2016, started with stolen credentials to a private source code repository, and ended with the theft of sensitive data on 57 million people, including both Uber customers, and drivers. 

The data that was stolen included full names, email addresses, and phone numbers, as well as driver license numbers, which cybercriminals can utilize to engage in identity theft, for example.

Even though the hack happened in 2016, it was only disclosed a year later. Allegedly, both the company CEO at the time, Travis Kalanick, and the Chief Security Officer (CSO), Joe Sullivan, knew of the breach and tried to cover it up, paying the hackers $100,000 to delete the data and never speak of it again. 

Kalanick was later ousted from his position, and succeeded by Dara Khosrowshahi who, upon learning of what had happened, fired Sullivan, and reported the whole thing to the authorities. 

Sullivan was also later charged with obstruction of justice, for trying to hide the breach from both the FTC and Uber management, with his trial set to begin in roughly a month. 

Another reason why the DoJ decided not to press criminal charges against Uber was because of an agreement the company made with the FTC in 2018, to report any future cyberattacks to the government. Uber had also paid $148 million to settle civil litigation that was tied to the data breach.

Via: The Verge

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
GrubHub app on a mobile phone
GrubHub reveals massive data breach - customers, drivers, businesses all affected, here's what we know
Outdoor photograph of a pair of hands holding a smartphone with navigator location points in the background
Millions of phone location records feared leaked as one of the biggest data leaks ever may be a whole lot worse
Suitcase next to a bed in a hotel
Millions of hotel users see personal info checked out in huge data leak
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection