Data Breaches

Uber Data Breach Affects 57 Million Rider and Driver Accounts

Written for Symantec

Uber Technologies, Inc. disclosed that hackers stole the personal information of some 57 million customers and drivers from the ride-sharing company, according to a report by Bloomberg News. The news outlet also reported that, for more than a year, Uber concealed news of the data breach, which was discovered in late 2016.

In a statement on its website and attributed to CEO Dara Khosrowshahi, the company said the information included:

  • The names and driver’s license numbers of around 600,000 drivers in the United States.
  • Some personal information of 57 million Uber riders and drivers around the world. This information included names, email addresses and mobile phone numbers.

Uber rider or driver? Here’s what you need to know:

For Uber riders, the company says it doesn’t believe individuals need to take action. “We have seen no evidence of fraud or misuse tied to the incident,” its statement to riders said. “We are monitoring the affected accounts and have flagged them for additional fraud protection.”

That said, it is possible for identity thieves to launch phishing attacks, appearing to come from Uber, hoping to trick customers into providing personal information, such as account credentials or payment card information. It’s always important to check the actual email address to ensure a message is from the company or person it appears to be from. Also, don’t click on an emailed link or attachment without verifying the email’s authenticity.Uber says it’s notifying its drivers whose driver’s license numbers were accessed and are providing them with free credit monitoring and identity theft protection services. It’s providing additional information for Uber drivers on its website.

How the Uber breach happened

Uber said two people who didn’t work for the company accessed the data on a third-party cloud-based service that Uber uses. The company also said that outside forensics experts have not seen evidence that the hackers accessed other types of information. Un-accessed information includes:

  • Trip location histories
  • Credit card numbers
  • Bank account numbers
  • Social Security numbers
  • Dates of birth

Bloomberg News reports that company executives originally paid the hackers $100,000 to delete the data and keep news of the data breach quiet. In its statement, Uber said that two individuals who led the original response to the incident are no longer with the company, effective Nov. 21, 2017, the date the company went public with news of the breach.

Symantec Corporation, the world’s leading cyber security company, allows organizations, governments, and people to secure their most important data wherever it lives. More than 50 million people and families rely on Symantec’s Norton and LifeLock comprehensive digital safety platform to help protect their personal information, devices, home networks, and identities.

Start your protection,
enroll in minutes.