Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2018

Careem's rapid growth left 14 million users' data exposed to hackers

Hackers took names, emails, phones and trip data of ~14 million Careem riders and drivers in January 2018. Careem disclosed the breach three months later.

Careem · 2018-01

What happened

Careem was the Middle East's answer to Uber — a Dubai-based ride-hailing app that had grown rapidly across more than a dozen countries, from the Gulf to North Africa, Pakistan and Turkey. Like other platforms, it held the personal data of millions of customers and the drivers who served them.

On 14 January 2018 Careem detected that its systems had been breached. Hackers had accessed the account data of about 14 million people — riders and drivers alike — taking names, email addresses, phone numbers and trip records. It was one of the largest data breaches reported in the region.

Careem did not announce the breach immediately. It disclosed it publicly on 23 April 2018, roughly three months after detection, saying it had needed time to investigate and had worked with law enforcement and security specialists. The gap drew the usual question about how quickly a company should tell its users.

The case is a reminder that fast-growing platforms are data targets before they are anything else. Careem had raced to add cities and users, and the personal information that came with that growth became an asset for attackers. The lesson is that security has to scale as fast as the user base, and that disclosure timing is itself part of the response.

Why it happened

  • Careem's rapid expansion across many countries accumulated the personal data of millions of riders and drivers faster than its defences were hardened against attackers.
  • A ride-hailing platform is a rich target: it holds names, contact details and movement data for a large, geographically spread user base in one place.
  • The breach was detected in January but disclosed only in April, leaving a three-month window in which affected users did not know their data had been taken.
  • Holding data on both riders and drivers doubled the exposure and meant the breach reached the people who earn their living through the platform, not just its customers.
What it cost14 million users' and drivers' data takenembarrassing

The lesson

A platform that races to add users is building a target as fast as a business. Personal data must be secured at the pace of growth, and when it is breached, telling users promptly is part of the fix.

Aftermath

Careem continued to operate and was later acquired by Uber, becoming the core of Uber's business across the region. The breach is cited in discussions of data security at high-growth technology companies in emerging markets, where user numbers can outstrip the security and disclosure practices that ought to accompany them.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →