Uber admits covering up 2016 hacking, avoids prosecution in U.S. settlement

Prosecutors said a former security chief arranged to pay the hackers $100,000 in Bitcoin to cover up the incident

July 23, 2022 09:42 am | Updated 06:42 pm IST

Uber admits covering up 2016 hacking, avoids prosecution in U.S. settlement

Uber admits covering up 2016 hacking, avoids prosecution in U.S. settlement | Photo Credit: REUTERS

Uber Technologies Inc on Friday accepted responsibility for covering up a 2016 data breach that affected 57 million passengers and drivers, as part of a settlement with U.S. prosecutors to avoid criminal charges.

(Sign up to our Technology newsletter, Today’s Cache, for insights on emerging themes at the intersection of technology, business and policy. Click here to subscribe for free.)

In entering a non-prosecution agreement, Uber admitted that its personnel failed to report the November 2016 hacking to the U.S. Federal Trade Commission, even though the agency had been investigating the ride-sharing company’s data security.

U.S. Attorney Stephanie Hinds in San Francisco said Uber waited about a year to report the breach, after installing new executive leadership who “established a strong tone from the top” regarding ethics and compliance.

Hinds said the decision not to criminally charge Uber reflected new management’s prompt investigation and disclosures, and Uber’s 2018 agreement with the FTC to maintain a comprehensive privacy program for 20 years.

The San Francisco-based company is also cooperating with the prosecution of a former security chief, Joseph Sullivan, over his alleged role in concealing the hacking.

Uber did not immediately respond to requests for comment.

Sullivan was originally indicted in September 2020. Prosecutors said Sullivan arranged to pay the hackers $100,000 in Bitcoin and have them sign non-disclosure agreements that falsely stated they had not stolen data.

Uber had a bounty program designed to reward security researchers who report flaws, but not to cover up data thefts.

In September 2018, Uber paid $148 million to settle claims by all 50 U.S. states and Washington, D.C., that it was too slow to disclose the hacking.

Uber shares closed down 93 cents at $23.30 on Friday. The non-prosecution agreement was disclosed after U.S. markets closed. 

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.