Back to the archive

The encyclopedia · Legal & Compliance · Legal decision · 2016–2018

Uber paid hackers $100K to hide a 2016 breach — 50 states fined it $148M for the cover-up

Hackers stole 57M riders' and 600K drivers' records in 2016. Uber paid them $100,000 to delete the data and stay quiet, hiding the breach for over a year.

Uber Technologies · 2018-09-26

What happened

In October 2016, two hackers accessed a private GitHub repository used by Uber engineers and found credentials that let them into a cloud storage account holding rider and driver data. They downloaded names, email addresses and phone numbers for 57 million Uber users, plus roughly 600,000 US drivers' license numbers.

Rather than disclose the breach, Uber routed a $100,000 payment to the hackers through its bug-bounty program — the channel meant for security researchers who responsibly report flaws — on condition they destroy the data and sign non-disclosure agreements. The company did not notify affected users, drivers or any regulator. The breach only became public in November 2017, over a year later, after new CEO Dara Khosrowshahi took over and disclosed it himself.

Attorneys general in all 50 states and Washington, D.C. investigated the concealment as a violation of state data-breach notification laws, which generally require timely disclosure once a breach is discovered. In September 2018 Uber agreed to pay $148 million — a record multistate settlement at the time — and to adopt a corporate integrity program, improve its data security practices, and submit to independent third-party assessments of how it protects user data.

Why it happened

  • Uber's engineers stored cloud credentials in a place accessible from a code repository, giving attackers a path from one system into another with sensitive user data.
  • Rather than disclose a confirmed breach, the company paid off the attackers through a program designed for a different purpose, treating the payment as a way to make the incident disappear.
  • State breach-notification laws set a clock running from discovery, not from when disclosure is convenient — Uber's year-long silence was itself the violation.
  • The concealment only ended when new leadership with no role in the original decision chose transparency over continuity with the prior response.
What it cost$148M multistate settlementcostly

The lesson

A breach is one incident; concealing it is a second, separate decision with its own legal exposure — paying attackers does not convert a cover-up into compliance.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →