Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityCybersecurity News

Uber Faces Investigations Following Data Breach, Cover-Up

November 22, 2017

Fifty-seven million customers’ and drivers’ personal data was stolen from Uber Technologies Inc in an October 2016 attack. The data includes names, email addresses and phone numbers of Uber riders around the world, plus the personal information of roughly 7 million drivers. Uber reports that no Social Security numbers, credit card information, trip location details or other data were taken.

This week, the ride-hailing company fired its chief security officer and one of his deputies for their roles in keeping the hack quiet, including a $100,000 payment to the attackers to delete the data, Bloomberg reports. Uber says it believes the stolen information was never used.

Following the company’s disclosure of the breach Tuesday, New York Attorney General Eric Schneider launched an investigation into the hack, and the company was also sued for negligence over the breach.

The breach involved two attackers accessing a private coding site used by Uber software engineers and using login credentials obtained there to access data stored on an Amazon Web Services account. From there, the hackers found cloud-stored rider and driver information, later emailing Uber asking for money, the company reported. Uber said it was obligated to report the hack of driver’s license information and failed to do so.

The company did, however, take immediate steps to secure the data and thwart further unauthorized access by those individuals, as well as implementing security measures to restrict access and strengthen controls on cloud-based storage, says Dara Khosrowshahi, who took over as CEO in September.

“None of this should have happened, and I will not make excuses for it,” said Khosrowshahi in an emailed statement. “We are changing the way we do business.”

The breach and subsequent failure to disclose are only part of a recent spate of scandals to hit Uber in the past year, including many executive shake-ups.

According to Jonathan Sander, Vice President, STEALTHbits Technologies:  “The attention in this newly revealed Uber breach will likely focus on how it was covered up and the executive suite drama that haunts Uber. But none of that is surprising. People in power often act to cover up their mistakes and Uber executive drama is cliché at this point. What is constantly shocking to me is that people continue to make the same mistakes over and over when it comes to security. This happened because of reused credentials, poorly secured sensitive information left in the wrong place, and a lack of discipline in access control that led to the developers having piles of user data to be stolen. Security pros would have flipped out with any one of those in play – and you can imagine exasperated security folks at Uber talking themselves blue in the face about it. But despite this security drama playing out over and over, the only drama people tune into is the executive suite’s machinations.”

However, Ryan Wilk, Vice President of Customer Success for NuData Security (a Mastercard company), sees a silver lining in Uber’s response: "While the news of the Uber breach is never something you want to hear, it is refreshing to see a company taking such quick and decisive action to earn back the consumers trust.  Uber CEO Dara Khosrowshahi’s statement that there is no excuse for what happened and that Uber will be putting integrity and trust at the core of every business decision is a welcome message."

KEYWORDS: cloud computing cybersecurity litigation data breach security credentials

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Opened padlock on computer keyboard

10 Data Breaches to Know About (April 2026)

Laptop with desktop screen showing

Research: Microsoft Edge Loads Stored Passwords in Cleartext

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

SEC Podcast Header Podcast

Credential Management in High Turnover Environments

Laptop in darkness

Reframing MFA Bypass: Four Identity Gaps Attackers Exploit

SEC 2026 Benchmark Banner

Events

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

June 10, 2026

Applying Agentic AI in Security Operations for Faster Decisions & Better Outcomes

Security teams have never had more visibility. We’ll explore how a new decision layer is helping security teams move from detection to decision. Turn alerts into decision-ready context, reducing reliance on manual triage and enabling faster action.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Equifax CEO Abruptly Retires Following Data Breach

    See More
  • laptop open with blue light

    66% of consumers would not trust a company following a data breach

    See More
  • cybersecurity

    Sixty-one Percent of UK IT Leaders Willing to Cover Up Data Breaches

    See More

Related Products

See More Products
  • security book.jpg

    Security Investigations: A Professional’s Guide

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing