The Freeman

Hackers stole data from 57M Uber riders, drivers — CEO

-

SAN FRANCISCO — Uber said yesterday that hackers compromise­d personal data from some 57 million riders and drivers in a breach kept hidden for a year."None of this should have happened, and I will not make excuses for it," said a statement from chief executive Dara Khosrowsha­hi, who took over at the ridesharin­g giant in August.

Two members of the Uber informatio­n security team who "led the response" that included not alerting users that their data was breached were let go from the San Francisco-based company effective Tuesday, according to Khosrowsha­hi.

The Uber chief said he only recently learned that outsiders had broken into a cloud-based server used by the company for data and downloaded a "significan­t" amount of informatio­n.

Stolen files included names, email addresses, and mobile phone numbers for riders, and the names and driver license informatio­n of some 600,000 drivers, according to Uber.

Uber paid the hackers $100,000 to destroy the data, not telling riders or drivers whose informatio­n was at risk, according to a source familiar with the situation.

Co-founder and ousted chief Travis Kalanick was advised of the breach shortly after it was discovered, but it was not made public until Uber's new boss Khosrowsha­hi learned of the incident.

"You may be asking why we are just talking about this now, a year later," Khosrowsha­hi said.

"I had the same question, so I immediatel­y asked for a thorough investigat­ion of what happened and how we handled it."

Khosrowsha­hi said that what he learned about Uber's failure to notify users or regulators prompted corrective actions.

"All companies would be wise to remember this: cock-ups are bad, but cover-ups can kill you," computer security specialist Graham Cluley said in a blog post.

"You can ask forgivenes­s for being hacked, but many people will find it harder to forgive and forget if you deliberate­ly concealed the truth from them."

Yahoo and Equifax were hit with criticism for how long it took the companies to disclose hacks.

"Breach disclosure is taking too long," said McAfee vice president of labs Vincent Weafer.

Weafer described Uber's decision to pay the hackers off as unusual, and questioned whether it was wise.

"You are relying on trust among thieves that the data has not been copied or leaked in any way," Weafer said.

Newspapers in English

Newspapers from Philippines