
The Uber data breach is sending shockwaves across the Silicon Valley and the world, after a series of leaks from Yahoo, Equifax, Malaysia and now at the ride hailing headquarters, just goes to show how vulnerable individual data acquired by these organisations really are.
In the case of Uber, it has been identified that 2 employees of the company was responsible for the leaks but questions are being asked why the 2016 incident purportedly known by the management not revealed. Dara Khosrowshahi, CEO who replaced Travis Kalanick early this year published a statement explaining the situation.
As Uber’s CEO, it’s my job to set our course for the future, which begins with building a company that every Uber employee, partner and customer can be proud of. For that to happen, we have to be honest and transparent as we work to repair our past mistakes.
I recently learned that in late 2016 we became aware that two individuals outside the company had inappropriately accessed user data stored on a third-party cloud-based service that we use. The incident did not breach our corporate systems or infrastructure.
Our outside forensics experts have not seen any indication that trip location history, credit card numbers, bank account numbers, Social Security numbers or dates of birth were downloaded. However, the individuals were able to download files containing a significant amount of other information, including:
The names and driver’s license numbers of around 600,000 drivers in the United States.
Some personal information of 57 million Uber users around the world, including the drivers described above. This information included names, email addresses and mobile phone numbers.
At the time of the incident, we took immediate steps to secure the data and shut down further unauthorized access by the individuals. We subsequently identified the individuals and obtained assurances that the downloaded data had been destroyed. We also implemented security measures to restrict access to and strengthen controls on our cloud-based storage accounts.
You may be asking why we are just talking about this now, a year later. I had the same question, so I immediately asked for a thorough investigation of what happened and how we handled it. What I learned, particularly around our failure to notify affected individuals or regulators last year, has prompted me to take several actions.
Since then Uber has taken courses of actions to address the leaks, including the sacking of the two individuals, notifying the drivers whose license numbers were downloaded. While there has been no evidence of fraud or misuse tied to the incident, the affected accounts are being monitored and given additional protection.
The CEO goes on to admit, that none of this should have happened, and will not make excuses for it.



