Uber is coming clean about its cover-up of a year-old hacking attack that stole personal information about more than 57 million of the beleaguered ride-hailing service’s customers and drivers. (AP Photo/Seth Wenig, File)

Uber is coming clean about its cover-up of a year-old hacking attack that stole personal information about more than 57 million of the beleaguered ride-hailing service’s customers and drivers. (AP Photo/Seth Wenig, File)

Uber reveals cover-up of hack affecting 57M riders, drivers

Uber acknowledges paying the hackers $100,000 to destroy the stolen information a year ago.

By Michael Liedtke / Associated Press

SAN FRANCISCO — Uber is coming clean about its cover-up of a year-old hacking attack that stole personal information about more than 57 million of the beleaguered ride-hailing service’s customers and drivers.

So far, there’s no evidence that the data taken has been misused, according to a Tuesday blog post by Uber’s recently hired CEO, Dara Khosrowshahi. Part of the reason nothing malicious has happened is because Uber acknowledges paying the hackers $100,000 to destroy the stolen information.

The revelation marks the latest stain on Uber’s reputation. It also brought an investigation from New York’s attorney general and threats of larger-than-normal fines from British authorities for failing to promptly disclose the hack.

The San Francisco company ousted Travis Kalanick as CEO in June after an internal investigation concluded he had built a culture that allowed female workers to be sexually harassed and encouraged employees to push legal limits.

It’s also the latest major breach involving a prominent company that didn’t notify the people that could be potentially harmed for months or even years after the break-in occurred.

Yahoo didn’t make its first disclosure about hacks that hit 3 billion user accounts during 2013 and 2014 until September 2016. Credit reporting service Equifax waited several months before revealing this past September that hackers had carted off the Social Security numbers of 145 million Americans.

Khosrowshahi criticized Uber’s handling of its data theft in his blog post.

“While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes,” Khosrowshahi wrote. “We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers.”

That pledge shouldn’t excuse Uber’s previous regime for its egregious behavior, said Sam Curry, chief security officer for the computer security firm Cybereason.

“The truly scary thing here is that Uber paid a bribe, essentially a ransom to make this breach go away, and they acted as if they were above the law,” Curry said. “Those people responsible for the integrity and confidentiality of the data in-fact covered it up.”

The heist took the names, email addresses and mobile phone numbers of 57 million riders around the world. The thieves also nabbed the driver’s license numbers of 600,000 Uber drivers in the U.S.

Uber waited until Tuesday to begin notifying the drivers with compromised driver’s licenses, which can be particularly useful for perpetrating identify theft. For that reason, Uber will now pay for free credit-report monitoring and identity theft protection services for the affected drivers.

Kalanick, who still sits on Uber’s board of directors, declined to comment on the data breach that took place in October 2016. Uber says the response to the hack was handled by its chief security officer, Joe Sullivan, a former federal prosecutor whom Kalanick lured away from Facebook in 2015.

As part of his effort to set things right, Khosrowshahi extracted Sullivan’s resignation from Uber and also jettisoned Craig Clark, a lawyer who reported to Sullivan.

Clark didn’t immediately respond to a request for comment sent through his LinkedIn profile. Efforts to reach Sullivan were unsuccessful.

On Wednesday, New York Attorney General Eric Schneiderman’s office confirmed that it had opened an investigation into the data theft, but a spokeswoman wouldn’t comment further. New York law requires that companies notify the attorney general and consumers if data is stolen.

In London, Britain’s Deputy Information Commissioner James Dipple-Johnstone said Wednesday the company faces “higher fines” because it concealed the hack from the public.

The Information Commissioner’s Office and the National Cyber Security Center are working to gauge the severity of the problem for British Uber users.

Uber’s silence about its breach came while it was negotiating with the Federal Trade Commission about its handling of its riders’ information.

Earlier in 2016, the company reached a settlement with the New York attorney general requiring it to take steps to be more vigilant about protecting the information that its app stores about its riders. As part of that settlement, Uber also paid a $20,000 fine for waiting to notify five months about another data breach that it discovered in September 2014.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

Paul Roberts makes a speech after winning the Chair’s Legacy Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Paul Roberts: An advocate for environmental causes

Roberts is the winner of the newly established Chair’s Legacy Award from Economic Alliance Snohomish County.

Laaysa Chintamani speaks after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Laasya Chintamani: ‘I always loved science and wanted to help people’

Chintamani is the recipient of the Washington STEM Rising Star Award.

Dave Somers makes a speech after winning the Henry M. Jackson Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
County Executive Dave Somers: ‘It’s working together’

Somers is the recipient of the Henry M. Jackson Award from Economic Alliance Snohomish County.

Mel Sheldon makes a speech after winning the Elson S. Floyd Award on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Mel Sheldon: Coming up big for the Tulalip Tribes

Mel Sheldon is the winner of the Elson S. Floyd Award from Economic Alliance Snohomish County

Craig Skotdal makes a speech after winning on Tuesday, April 22, 2025 in Tulalip, Washington. (Olivia Vanni / The Herald)
Craig Skotdal: Helping to breathe life into downtown Everett

Skotdal is the recipient of the John M. Fluke Sr. award from Economic Alliance Snohomish County

The Coastal Community Bank branch in Woodinville. (Contributed photo)
Top banks serving Snohomish County with excellence

A closer look at three financial institutions known for trust, service, and stability.

Image from Erickson Furniture website
From couch to coffee table — Local favorites await

Style your space with the county’s top picks for furniture and flair.

2025 Emerging Leader winner Samantha Love becomes emotional after receiving her award on Tuesday, April 8, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Samantha Love named 2025 Emerging Leader for Snohomish County

It was the 10th year that The Herald Business Journal highlights the best and brightest of Snohomish County.

2025 Emerging Leader Tracy Nguyen (Olivia Vanni / The Herald)
Tracy Nguyen: Giving back in her professional and personal life

The marketing director for Mountain Pacific Bank is the chair for “Girls on the Run.”

2025 Emerging Leader Kellie Lewis (Olivia Vanni / The Herald)
Kellie Lewis: Bringing community helpers together

Edmonds Food Bank’s marketing and communications director fosters connections to help others.

2025 Emerging Leader Christina Strand (Olivia Vanni / The Herald)
Christina Strand: Helping people on the move

Community engagement specialist believes biking, walking and public transit can have a positive impact.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.