Breach report
Travel & HospitalityUber
Uber hid a hack that exposed data of 57 million users and drivers for more than a year
Uber revealed in November 2017 that hackers had stolen data on 57 million riders and drivers a year earlier, and that the company had paid the attackers $100,000 to delete the data and keep quiet.
Reported by CNBC
Records exposed
57M
57 million riders and drivers
Scale vs. largest on file
- When
- 2016 (disclosed 2017)
- How they got in
- Stolen cloud credentials found in a private GitHub repository
- Sector
- Travel & Hospitality
In late 2016, two hackers gained access to a private code repository used by Uber engineers on GitHub. Inside, they found credentials for the company's Amazon Web Services account, which they used to download an archive of rider and driver information stored in the cloud. They then contacted Uber and demanded payment. Rather than notify regulators and affected users, Uber paid the hackers $100,000, routed through its bug bounty program, and had them sign nondisclosure agreements.
The breach exposed names, email addresses and mobile phone numbers of about 50 million riders around the world, as well as personal information on roughly 7 million drivers, including about 600,000 US driver's license numbers. Uber said Social Security numbers, credit card details, trip location histories and dates of birth were not taken.
The incident stayed secret until November 21, 2017, when new chief executive Dara Khosrowshahi disclosed it, saying it should never have happened. Uber fired chief security officer Joe Sullivan and one of his deputies for their role in concealing the breach. The disclosure came while Uber was already negotiating with the Federal Trade Commission over earlier privacy lapses, and at a time when US law in many states required notification of breaches involving driver's license numbers.
The consequences were extensive. In 2018 Uber agreed to pay $148 million in a settlement with all 50 US states and the District of Columbia, and it expanded its FTC settlement. Data protection authorities in the UK and the Netherlands fined the company. The two hackers pleaded guilty in 2019 to charges related to the extortion scheme. In a landmark case, Sullivan was convicted in 2022 of obstructing an FTC investigation and concealing a felony, becoming one of the first corporate security executives to face criminal charges over handling a breach; he was sentenced to probation in 2023. Uber itself entered a non-prosecution agreement in 2022 that included an admission of responsibility for the cover-up.
The Uber case changed how security leaders think about breach response. It showed that the cover-up can be far more damaging than the intrusion, and that disguising extortion payments as bug bounties invites personal liability. It also highlighted the risk of storing secrets such as cloud keys in code repositories.