Uber paid hackers $100,000 to cover up massive data breach: CEO

Published November 23, 2017
DARA Khosrowshahi says he learnt about the breach recently.—Reuters
DARA Khosrowshahi says he learnt about the breach recently.—Reuters

WASHINGTON: Uber Techno­logies paid hackers $100,000 to keep secret a massive breach last year that exposed the personal information of about 57 million accounts of the ride-service provider, the company said on Tuesday.

Discovery of the US company’s cover-up of the incident resulted in the firing of two employees responsible for its response to the hack, said Dara Khosrowshahi, who replaced co-founder Travis Kalanick as chief executive in August.

“None of this should have happened, and I will not make excuses for it,” Khosrowshahi said in a blog post.

The breach occurred in Octo­ber last year, but Khosrowshahi said he had learned of it recently.

The hack is another controversy for Uber on top of sexual harassment allegations, a lawsuit alleging trade secret theft and multiple federal criminal probes that culminated in Kalanick’s ouster in June.

The stolen information included names, email addresses and mobile phone numbers of Uber users around the world, and the names and licence numbers of 600,000 US drivers, Khosrowshahi added.

Uber passengers need not worry as there was no evidence of fraud, while drivers whose licence numbers had been stolen would be offered free identity theft protection and credit monitoring, Uber said.

Two hackers gained access to proprietary information stored on GitHub, a service that allows engineers to collaborate on software code. There, the two people stole Uber’s credentials for a separate cloud-services provider where they were able to download driver and rider data, the company said.

A GitHub spokeswoman said the hack was not the result of a failure of GitHub’s security.

“While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes,” Khosrowshahi said.

“We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers.”

Bloomberg News first reported the data breach on Tuesday.

The Uber chief said the firm had begun notifying regulators. The New York attorney general has opened an investigation, a spokeswoman said.

Regulators in Australia and the Philippines said on Wednesday they would look into the matter. Uber is seeking to mend fences in Asia after having run-ins with authorities, and is negotiating with a consortium led by Japan’s SoftBank Group for fresh investment. SoftBank declined to comment.

Uber said it had fired its chief security officer, Joe Sullivan, and a deputy, Craig Clark, this week because of their role in the handling of the incident. Sullivan, formerly the top security official at Facebook and a federal prosecutor, served as both security chief and deputy general counsel for Uber.

Kalanick, the former Uber chief, learned of the breach in November last year, a month after it took place, a source familiar with the matter said. At the time, the company was negotiating with the US Federal Trade Commission over the handling of consumer data.

A board committee had investigated the breach and concluded that neither Kalanick nor Salle Yoo, Uber’s general counsel at the time, were involved in the cover-up, another person familiar with the issue said.

Uber said on Tuesday it was obliged to report the theft of the drivers’ licence information and had failed to do so.

Kalanick, through a spokesman, declined to comment. The former CEO remains on the Uber board of directors, and Khosrowshahi has said he consults him regularly.

Crime pays

Although payments to hackers are rarely publicly discussed, US Federal Bureau of Investigation officials and private security companies have said an increasing number of companies are paying criminal hackers to recover stolen data.

“The economics of being a bad guy on the internet today are incredibly favourable,” said Oren Falkowitz, co-founder of California-based cyber security company Area 1 Security.

Uber has a history of failing to protect driver and passenger data. Hackers previously stole information about Uber drivers and the company acknowledged in 2014 that its employees had used a software tool called “God View” to track passengers.

Dara Khosrowshahi, the new CEO, said on Tuesday he had hired Matt Olsen, former general counsel of the US National Security Agency, to restructure the company’s security teams and processes.

The company also hired Mandiant, a cybersecurity firm owned by FireEye, to investigate the breach.

The new chief executive has travelled the world since replacing Kalanick to deliver a message that Uber has matured from its earlier days as a rule-flouting startup.

Published in Dawn, November 23rd, 2017

Follow Dawn Business on Twitter, LinkedIn, Instagram and Facebook for insights on business, finance and tech from Pakistan and across the world.

Opinion

The Dar story continues

The Dar story continues

One wonders what the rationale was for the foreign minister — a highly demanding, full-time job — being assigned various other political responsibilities.

Editorial

Wheat protests
Updated 01 May, 2024

Wheat protests

The government should withdraw from the wheat trade gradually, replacing the existing market support mechanism with an effective new one over the next several years.
Polio drive
01 May, 2024

Polio drive

THE year’s fourth polio drive has kicked off across Pakistan, with the aim to immunise more than 24m children ...
Workers’ struggle
Updated 01 May, 2024

Workers’ struggle

Yet the struggle to secure a living wage — and decent working conditions — for the toiling masses must continue.
All this talk
Updated 30 Apr, 2024

All this talk

The other parties are equally legitimate stakeholders in the country’s political future, and it must give them due consideration.
Monetary policy
30 Apr, 2024

Monetary policy

ALIGNING its decision with the trend in developed economies, the State Bank has acted wisely by holding its key...
Meaningless appointment
30 Apr, 2024

Meaningless appointment

THE PML-N’s policy of ‘family first’ has once again triggered criticism. The party’s latest move in this...