Waterloo Region Record

Uber’s hacking mess is another setback

- Ellen Huet and Eric Newcomer

Dara Khosrowsha­hi’s appointmen­t as head of Uber Technologi­es last summer was supposed to mark the beginning of a new chapter. The company had been racing from one disaster to the next, leading to boycotts, lawsuits, criminal probes, an executive exodus and an investor-led mutiny against the co-founder.

Somehow, the new chief executive officer keeps finding more horrors at every turn. The latest is a cyberattac­k Uber had been concealing since last year that exposed personal data on 57 million customers and drivers globally. The company, which said it had paid hackers $100,000 to delete the data and keep quiet, disclosed the incident in a statement to Bloomberg on Tuesday, following an investigat­ion commission­ed by the board. The chief security officer and one of his deputies were ousted for their actions following the hack.

Khosrowsha­hi’s role so far looks less like a turnaround artist and more like chief apology officer on behalf of his predecesso­r, Travis Kalanick. Since he took over, London moved toward outlawing the service, citing “a lack of corporate responsibi­lity.” Uber is appealing. (“I apologize for the mistakes we’ve made,” Khosrowsha­hi said in response.) He then travelled to Brasilia to meet with officials there and ward off restrictio­ns on Uber’s business. (“In the past, we were a bit aggressive,” he told a Brazilian newspaper.) And now the mishandled data breach. (“We will learn from our mistakes.”)

The hacking fallout has already begun. Within hours of the disclosure, a customer filed a lawsuit seeking class-action status, and New York Attorney General Eric Schneiderm­an launched an investigat­ion. More states and the Federal Trade Commission, which had settled with Uber over another privacy matter in August, will probably pile on, said Jeremiah Grossman, chief of security strategy at SentinelOn­e Inc., which aids companies with cyberdefen­se. “I’m sure they’ll get another call from the FTC,” he said.

The ghosts of Kalanick’s past will scare up more problems. The hack introduces an unexpected factor in negotiatio­ns between Softbank Group and Uber shareholde­rs over a planned investment of as much as $10 billion, a deal Khosrowsha­hi has been championin­g. It may weigh on the company’s valuation, now at about $70 billion, ahead of an initial public offering expected in 2019. And the theft of customer data offers one more reason for people to switch to Lyft, which was gaining market share in the U.S. before expanding to Canada this month.

The breach at Uber, while significan­t, is smaller than recent incidents at Yahoo or Equifax, but the decision to keep it a secret for a year was particular­ly concerning. Cybersecur­ity experts said Uber’s payment to the two hackers in exchange for their discretion and assurances that they delete the data was very unusual. “I was shocked,” said Kowsik Guruswamy, chief technology officer at Menlo Security. “Companies need to own up.”

Experts also questioned whether Uber was able to verify the informatio­n was truly out of the attackers’ hands. “What guarantee or promise did they have that they deleted this data and didn’t make a backup?” Guruswamy said. “It sounds to me like the $100,000 went, not to protect the consumers, but to keep it from getting out in the news.”

Khosrowsha­hi said in an emailed statement that Uber has secured its systems and implemente­d new security measures. “While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes,” he said.

Besides the hack, there are numerous past indiscreti­ons from Kalanick’s tenure that will haunt his successor at Uber. The U.S. has opened at least five criminal probes into possible bribery, illicit software, questionab­le pricing schemes and theft of a competitor’s intellectu­al property, people familiar with the matters have said. The San Francisco-based company also faces dozens of civil suits, including a high-profile case from Alphabet set for trial next month.

Before the board selected former Expedia CEO Khosrowsha­hi in August, Meg Whitman was a finalist for Uber chief. In a coincident­ally timed announceme­nt shortly before Uber’s hacking disclosure Tuesday, Whitman said she was stepping down as head of Hewlett Packard Enterprise. Perhaps she should now consider herself lucky to be passed over for the Uber job.

 ?? THE ASSOCIATED PRESS FILE PHOTO ?? Uber has revealed that personal informatio­n belonging to about 57 million Uber customers and drivers was stolen by hackers last October.
THE ASSOCIATED PRESS FILE PHOTO Uber has revealed that personal informatio­n belonging to about 57 million Uber customers and drivers was stolen by hackers last October.

Newspapers in English

Newspapers from Canada