Uber’s Data Breach

According to an article reported by Bloomberg earlier today, it seems Uber had gone through a data breach back in 2016. The hackers stole personal data accumulating to 57 million customers and drivers, which was kept hidden from the general public for over a year.

In an attempt to keep the leak contained, a US$100,000 payment was made to the hackers in order to keep them quiet. This comes to light after Uber had let go of its chief security officer along with one of his deputies.

The attack occurred on October 2016, which included names, email addresses and phone numbers of 50 million Uber riders from all around the world. Also included were the personal data and information of 7 million drivers and some 600,000 U.S. driver’s license numbers. A silver lining from this hack was that no Social Security numbers, credit card information, trip location details or other personal data were leaked.

In a separate article written by Sophos, its Principal Research Scientist Chester Wisniewski had this to say,

Uber’s breach demonstrates once again how developers need to take security seriously and never embed or deploy access tokens and keys in source code repositories. I would say it feels like I have watched this movie before, but usually organizations aren’t caught while actively involved in a cover-up. Putting the drama aside and the potential impacts from the upcoming GDPR enforcement, this is just another development team with poor security practices that has shared credentials. Sadly, this is common more often than not in agile development environments.”

(Source: Bloomberg, Sophos)

Share this post:

Comment what you think!