Uber Says No Evidence Hackers Took Rider Credit Card Numbers

Advertisement
By Associated Press | Updated: 14 December 2017 09:41 IST

An outside cyber-security firm hired by Uber after a massive data theft found no evidence that rider credit card, bank account or Social Security numbers were downloaded by two hackers, the company said in a response to demands for information from US senators.

But the ride-hailing company disclosed that in some cases, the hackers got location information from the place where people signed up for Uber, as well as heavily encoded versions of user passwords.

On November 21, Uber disclosed that names, email addresses and mobile-phone numbers of 57 million drivers and riders had been stolen. In a letter to four Republican senators led by Commerce Committee Chairman John Thune of South Dakota, the company says that Mandiant, the security firm, found 32 million of those are outside the US and 25 million are inside. Of the total, 7.7 million are drivers, mostly in the US, and hackers got driver's license numbers for 600,000 of them, according to the letter from new Uber CEO Dara Khosrowshahi.

Advertisement

The ride-hailing company also said it has not seen evidence of fraud or misuse of data taken in the breach, which lasted more than a year before being disclosed. Two employees were fired for not disclosing the theft to "appropriate parties," the letter said.

Advertisement

The hackers emailed Uber's US security team anonymously on November 14, 2016 telling them about the breach and demanding a payment. Uber tracked down the breach in private cloud data stored on Amazon's web services and shut down access, which came through a "compromised credential," the letter said.

The security team agreed to pay $100,000 (roughly Rs. 64.2 lakhs) to the hackers for an agreement to delete the data, and later tracked down the hackers' real names. Both signed documents assuring that the stolen data was destroyed, Khosrowshahi wrote. Team members found that the hackers first gained access on October 13, 2016, and there was no further access after Nov. 15, 2016, the letter said.

Advertisement

Uber notified the US Attorney's offices in San Francisco and Manhattan, as well as other government agencies, on November 21 of this year, but it's not clear whether any criminal investigation has been started. Neither office confirmed nor denied an investigation.

Uber installed additional protections to stop hackers, including a two-step authentication for one of the services that was hacked, the letter said.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Apps, Uber, Dara Khosrowshahi, Uber Hack
Advertisement

Related Stories

Popular Mobile Brands
  1. We Live in Time OTT Release: When, Where to Watch the Andrew Garfield Starrer
  1. NASA Experiment Shows Martian Ice Could Preserve Signs of Ancient Life
  2. MIT Detects Traces of a Lost ‘Proto Earth’ Deep Beneath Our Planet’s Surface
  3. Astronomers Detect Heavy Water in Planet-Forming Disk Around Young Star
  4. Global Projects Aim to Save Sinking Cities From Rising Seas and Climate Change
  5. NASA Confirms Brightening Comet SWAN Could Be Visible With Binoculars: When and Where to See It
  6. We Live in Time OTT Release: When, Where to Watch the Andrew Garfield and Florence Pugh Romance
  7. Imbam Is Now Streaming Online: Know Everything About This Deepak Parambol Starrer Malayali Drama
  8. Mysterious Asteroid Impact Found in Australia, But the Crater is Missing
  9. Thanal Comes to OTT: Everything You Need to Know About This Tamil Action Thriller
  10. Madam Sengupta Is Now Streaming: Know Where to Watch This Bangla Crime Thriller
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.