Uber to pay $148 million to settle data breach cover-up

Uber to pay $148 million to settle data breach cover-up

by Joseph Anthony
89 views

Uber Technologies Inc will pay $148 million for failing to disclose a massive data breach in 2016, marking a costly resolution to one of the biggest embarrassments and legal tangles the ride-hailing company has suffered.


The settlement with 50 US states and Washington, DC brings closure to one of several high-stakes legal battles Uber is seeking to resolve before an initial public offering next year, while also delivering a national rebuke against Uberโ€™s history of flouting laws and basic business ethics.

The amount is the largest among attorneys general settlements in privacy cases. By comparison, the multi-state settlement with Target Corp in 2017, over a breach in which 41 million people had their data stolen, was $18.5 million.

The settlement follows a 10-month investigation into a data breach that exposed personal data from 57 million Uber accounts, including 600,000 driverโ€™s license numbers. Uberโ€™s new Chief Executive Dara Khosrowshahi disclosed the breach in November, more than a year after the company was hacked under the previous CEO. Khosrowshahi has said the incident should have been disclosed to regulators at the time it was discovered in 2016.

The cover-up, widely seen by states as violating data breach reporting and data security laws, drew the ire of authorities across the United States and also in the United Kingdom, Australia and the Philippines. About half of the data breach victims lived in the United States.

The settlement terms include changes to Uberโ€™s business practices aimed at preventing future breaches and reforming its corporate culture. Uber will be required to report any data security incidents to states on a quarterly basis for the next two years, and implement a comprehensive information security program overseen by an executive officer who advises executive staff and Uberโ€™s board of directors.

โ€œWe know that earning the trust of our customers and the regulators we work with globally is no easy feat,โ€ said Uber Chief Legal Officer Tony West. โ€œWeโ€™ll continue to invest in protections to keep our customers and their data safe and secure, and weโ€™re committed to maintaining a constructive and collaborative relationship with governments around the world.โ€


In November 2016, Uber paid the hackers โ€“ who included a 20-year-old Florida man and a hacker in Canada โ€“ $100,000 to destroy the stolen data, using its โ€œbug bountyโ€ program, which is designed to reward security researchers who report flaws in a companyโ€™s software. Uber then chose not to report the matter to victims or authorities.

โ€œUberโ€™s decision to cover up this breach was a blatant violation of the publicโ€™s trust,โ€ said California Attorney General Xavier Becerra. โ€œConsistent with its corporate culture at the time, Uber swept the breach under the rug in deliberate disregard of the law.โ€

California, one of lead states in the settlement effort, will keep $26 million, to be split between the state Attorney Generalโ€™s Office and the San Francisco District Attorneyโ€™s Office, a spokeswoman for Becerraโ€™s office said.

Khosrowshahi fired two of Uberโ€™s top security officials when he announced the breach, and other members of that team have since departed. The company recently hired a chief privacy officer and chief security officer.

It still faces lawsuits from riders, drivers and the cities of Chicago and Los Angeles over the data breach.

You may also like

Leave a Comment

Chijos News is an independent online publication that provides readers with the latest breaking Nigerian news, world news, entertainment, sports, business, and many more.

@2024 – Chijosnews.com. All Rights Reserved.

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00