Los Angeles Times

Uber concealed hack, L.A. says

City attorney says ride-hailing firm broke law by not promptly reporting data breach.

- By Laura J. Nelson

For more than a year, Uber Technologi­es Inc. concealed a massive hack that exposed the personal data of millions of drivers and riders, violating a California law that requires companies to promptly report such breaches, according to a lawsuit filed Monday by Los Angeles City Atty. Mike Feuer.

In October 2016, hackers stole the names, cellphone numbers and email addresses of more than 57 million riders across the world, as well as driver’s license numbers for 600,000 Uber drivers in the United States. Uber disclosed the hack last month.

Feuer filed the lawsuit in Los Angeles County Superior Court on behalf of California residents. The case will

focus on Uber’s failure to disclose the data breach to Uber’s California drivers, he said.

California law requires companies to report hacks “in the most expedient time possible” and “without unreasonab­le delay” when some forms of personal data, including driver’s license numbers, are compromise­d. The law is designed to help consumers fight identity theft.

Instead, Uber paid the hackers $100,000 to destroy the data, pressured them to sign nondisclos­ure agreements, and portrayed the ransom as a payment to test the vulnerabil­ities of the company’s data security systems, according to the lawsuit.

“We’re taking action because we believe very strongly in the importance of protecting consumers,” Feuer said Monday at a news conference at City Hall.

The consumer protection law is commonly invoked in the lawsuits that follow data breaches. In September, San Francisco’s city attorney cited the law in a suit filed against Equifax, alleging the company failed to promptly disclose a hack that affected more than 15 million California residents.

Feuer said he doesn’t yet know how many drivers in California were affected in the Uber hack.

The lawsuit seeks $2,500 for each violation of the law. Any payments would be shared between the city and the county of Los Angeles, and would be spent on consumer protection efforts, Feuer said.

In a statement, an Uber spokespers­on said the company is happy to address regulators’ questions, and is “committed to changing the way we do business, putting integrity at the core of every decision we make, and working hard to regain the trust of consumers.”

Uber Chief Executive Dara Khosrowsha­hi, who was hired in August to replace controvers­ial founder Travis Kalanick, said in a blog post last month that he learned of the hack months after it occurred.

Uber’s chief of security and another employee were fired for not revealing the hack, and the company has provided free credit monitoring and identity theft protection to affected drivers, Khosrowsha­hi said.

“None of this should have happened, and I will not make excuses for it,” Khosrowsha­hi said. “While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes.”

The hack did not expose Uber riders’ trip histories, credit card numbers, bank account numbers, Social Security numbers or dates of birth, he said.

In January 2016, Uber paid a $20,000 fine to the New York attorney general for failing to promptly report a separate data breach in 2014. That previous disclosure, Monday’s lawsuit said, makes the company’s “gross conduct ... even more alarming.”

 ?? Mel Melcon Los Angeles Times ?? LOS ANGELES City Atty. Mike Feuer announces the filing of a lawsuit against Uber Technologi­es Inc. over its concealmen­t of a massive data breach in 2016.
Mel Melcon Los Angeles Times LOS ANGELES City Atty. Mike Feuer announces the filing of a lawsuit against Uber Technologi­es Inc. over its concealmen­t of a massive data breach in 2016.
 ?? Eric Risberg Associated Press ?? UBER’S headquarte­rs in San Francisco. The company paid the hackers $100,000 to destroy the data, according to the lawsuit filed by L.A. City Atty. Mike Feuer.
Eric Risberg Associated Press UBER’S headquarte­rs in San Francisco. The company paid the hackers $100,000 to destroy the data, according to the lawsuit filed by L.A. City Atty. Mike Feuer.
 ?? David Butow For The Times ?? AN UBER DRIVER on an L.A. street. In October 2016, hackers stole informatio­n on more than 57 million riders across the world, as well as driver’s license numbers for 600,000 Uber drivers in the United States.
David Butow For The Times AN UBER DRIVER on an L.A. street. In October 2016, hackers stole informatio­n on more than 57 million riders across the world, as well as driver’s license numbers for 600,000 Uber drivers in the United States.

Newspapers in English

Newspapers from United States