Skip to main content

Inside the hack Uber didn’t want 57 million users to know about

The man responsible for the Uber hack is reportedly a 20-year-old Floridian

Another day, another massive data breach. This time around, Uber was the target, but unlike other hacks, it took the company more than a year to disclose the hack to its customers.

More information is now coming to light about the attack, and Reuters reports that the culprit was a 20-year-old Florida man. As previously reported, this individual was then paid to destroying the evidence of the attack by way of a bug bounty program. While bug bounties are generally paid to folks who discover small vulnerabilities in a company’s code, this was clearly something much larger and more insidious.

Recommended Videos

A HackerOne executive noted that the alleged $100,000 payment could be an “all-time record.” Other security experts noted that paying a hacker who had committed a crime by stealing data would be highly unusual, particularly for a bug bounty program where computer scientists are typically paid somewhere between $5,000 and $10,000.

According to a blog post from Uber, hackers managed to steal the personal data of a whopping 57 million Uber users in a data breach. Among those compromised, according to a Bloomberg report, were 7 million drivers, of which around 600,000 had their drivers license numbers stolen. Uber says that the information did not include things like Social Security numbers or credit cards.

Uber didn’t keep the hack under wraps because it didn’t know about it, however. The Bloomberg report notes that former Uber CEO and co-founder Travis Kalanick was alerted to the breach in November 2016, only a month after the hack took place. An additional report from The Wall Street Journal further revealed that Uber’s new CEO Dara Khosrowshahi was alerted to the breach in early September, two weeks after he officially stepped in as the head of the company. Once he learned of the hack, he is said to have “immediately ordered an investigation, which he wanted to complete before making the matter public.”

At the time of the hack, Uber was already negotiating with investigators for separate privacy violation claims — and it still failed to report the hack.

“None of this should have happened, and I will not make excuses for it. While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes,” said Khosrowshahi, who took over in September, in the blog post. “We are changing the way we do business.”

Despite concealing the hack for a year, it does seem as though Uber is telling the truth in saying that it’s “changing the way it does business.” Bloomberg reports that the company ousted Joe Sullivan, its chief security officer, and one of Sullivan’s deputies for their roles in covering up the data breach, which is at least a first step in changing its ways. The Uber blog mentioned that “two of the individuals that led the response to this incident are no longer with the company.”

This is not the first massive data breach of the year. Earlier in 2017, credit reporting agency Equifax was breached, potentially putting at risk the information of a whopping 143 million U.S. residents. The hack itself took place sometime between May and July, but was disclosed in September.

Update: The Uber hacker is reportedly a 20-year-old Florida man. 

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
There’s something Samsung didn’t tell you about the Galaxy S24
The Samsung Galaxy S24 Ultra in its launch colors.

“Look, dude, I don’t know how they are going to manage the costs of licensing from AI companies and cloud partnerships, among other associated factors. Nothing comes free.” That’s what a machine learning engineer told me a few days ago when I explained to him how Qualcomm and MediaTek are bringing some neat generative AI tricks to phones.

Well, Samsung has confirmed those fears and quietly dropped the bombshell that at least some of its snazzy AI tricks for the Galaxy S24 series phones will eventually ask you to cough up some cash. That’s going to happen next year, but we don’t know how much you'll have to pay and in what way — at least not right now.

Read more
I wore a $2,750 smartwatch and I didn’t want to take it off
The Tag Heuer Connected Calibre E4 Bright Black Edition on a person's wrist.

Yes, the Tag Heuer Connected Calibre E4 Bright Black smartwatch costs $2,750, and if I had that kind of cash hanging about, I wouldn't hesitate to splurge on it. Madness, you may be saying, as some of the best smartwatches you can buy cost less than $400.

But the Tag Heuer is special, where others simply are not, and an upgrade to Wear OS 3 has really helped emphasize the sheer quality of this smartwatch. Let me try and explain why the expensive Tag Heuer smartwatch is still worth buying.
Fantastic design, materials, and finish

Read more
Personal data of 69 million Neopets users is now up for sale after a data breach
Person typing on a computer keyboard.

Neopets, an aged website that lets users keep virtual pets and take care of them, just suffered a major data breach. Aside from the personal data of over 69 million users, the hacker was able to obtain the website's source code.

This isn't the first time Neopets has faced a massive leak, but this time around, user data is currently being sold for crypto -- and the leak includes more than just usernames and passwords.

Read more