The encyclopedia · Legal & Compliance · Legal decision · 2018
Careem's rapid growth left 14 million users' data exposed to hackers
Hackers took names, emails, phones and trip data of ~14 million Careem riders and drivers in January 2018. Careem disclosed the breach three months later.
Careem · 2018-01
What happened
Careem was the Middle East's answer to Uber — a Dubai-based ride-hailing app that had grown rapidly across more than a dozen countries, from the Gulf to North Africa, Pakistan and Turkey. Like other platforms, it held the personal data of millions of customers and the drivers who served them.
On 14 January 2018 Careem detected that its systems had been breached. Hackers had accessed the account data of about 14 million people — riders and drivers alike — taking names, email addresses, phone numbers and trip records. It was one of the largest data breaches reported in the region.
Careem did not announce the breach immediately. It disclosed it publicly on 23 April 2018, roughly three months after detection, saying it had needed time to investigate and had worked with law enforcement and security specialists. The gap drew the usual question about how quickly a company should tell its users.
The case is a reminder that fast-growing platforms are data targets before they are anything else. Careem had raced to add cities and users, and the personal information that came with that growth became an asset for attackers. The lesson is that security has to scale as fast as the user base, and that disclosure timing is itself part of the response.
Why it happened
- Careem's rapid expansion across many countries accumulated the personal data of millions of riders and drivers faster than its defences were hardened against attackers.
- A ride-hailing platform is a rich target: it holds names, contact details and movement data for a large, geographically spread user base in one place.
- The breach was detected in January but disclosed only in April, leaving a three-month window in which affected users did not know their data had been taken.
- Holding data on both riders and drivers doubled the exposure and meant the breach reached the people who earn their living through the platform, not just its customers.
The lesson
A platform that races to add users is building a target as fast as a business. Personal data must be secured at the pace of growth, and when it is breached, telling users promptly is part of the fix.
Aftermath
Careem continued to operate and was later acquired by Uber, becoming the core of Uber's business across the region. The breach is cited in discussions of data security at high-growth technology companies in emerging markets, where user numbers can outstrip the security and disclosure practices that ought to accompany them.
Sources
- Careem says data of 14 million drivers and riders stolen in cyberattack — CNBC
- Ride-sharing platform Careem says hit by cyber attack with data of up to 14 million users stolen — The National
- Hackers access personal data of 14 million Careem taxi users — Arab News
- Careem Data Breach Exposes Data Of 14 Million Users — Tom's Hardware
spotted an error? The club wants to know.
More like this
HP India rigged government tenders through its resellers — ₹142.37 crore CCI fine
Amazon's €746M GDPR record fine was scrapped on a technicality
AliExpress got a €550M EU fine — the DSA's first big test landed on Alibaba
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.