The Prince George Citizen

Uber under fire after hackers steal data

- Ian BICKIS

TORONTO — Privacy advocates are raising alarms at how Uber is handling a year-old security breach that saw hackers steal the personal informatio­n of millions of customers around the world.

Uber admitted Tuesday that hackers stole names, email addresses and mobile phone numbers of 57 million riders but has still not said which customers had their data stolen including the number of Canadians affected.

The company said Wednesday that its priority was disclosing informatio­n to regulators, though it has known about the breach for close to a year.

“We are working closely with regulatory and government authoritie­s globally, including the Federal Privacy Commission­er’s Office here in Canada. Until we complete that process we aren’t in a position to get into more detail,” said Uber Canada spokesman Jean-Christophe de le Rue by email.

The company has so far specified only that hackers took the driver’s license numbers of 600,000 Uber drivers in the U.S. and that it has not seen evidence of fraud or misuse tied to the incident.

Uber also said that as of Tuesday, two of the individual­s who led the response to this incident are no longer with the company.

New York’s state Attorney General has confirmed it has opened an investigat­ion into the breach, with state laws requiring companies to give notice if data is stolen.

The company also faces potentiall­y higher than usual fines from British authoritie­s because the firm did not promptly disclose the hack as required by laws in the U.K.

Canada, however, does not have laws requiring disclosure of data breaches, and the Privacy Commission­er of Canada said it has not yet launched a formal investigat­ion.

The agency is, however, reaching out to its internatio­nal counterpar­ts to discuss the matter, and has asked Uber to provide a written breach report including details on how the breach happened and the impact on Canadian, said Privacy Commission­er spokeswoma­n Valerie Lawton by email.

NDP public safety critic Matthew said the Uber breach is the latest reminder that Canada needs to update its laws to deal with the growing threat of data theft.

“This type of hack is once again a reminder that the government needs to listen to the Privacy Commission­er and implement fines for companies who treat Canadians’ informatio­n this way. The law also needs to be changed to force companies to divulge these hacks and be transparen­t.”

The spate of cybersecur­ity breaches from Yahoo to Equifax show that more regulation is needed and the threat of reputation­al damage isn’t enough to force companies to act, said Benoit Dupont, Canada Research Chair in Cybersecur­ity at McGill University.

“Twenty years of looking at hacks shows that the markets aren’t good – the government is going to have to be a bit more assertive about how it directs and regulates companies to implement more stringent levels of cybersecur­ity.”

The long-delayed announceme­nt and lack of details so far goes against the importance of transparen­cy in these matters, said Satyamoort­hy Kabilan, director of national security at the Conference Board of Canada.

“That hiding of things, or that lack of communicat­ion over the breach, that is certainly a major concern for me.”

 ?? CP FILE PHOTO ?? The Uber app is displayed on an iPhone as taxi drivers wait for passengers at Vancouver Internatio­nal Airport on March 7.
CP FILE PHOTO The Uber app is displayed on an iPhone as taxi drivers wait for passengers at Vancouver Internatio­nal Airport on March 7.

Newspapers in English

Newspapers from Canada