In October 2016, hackers were able to steal the full names, addresses and phone numbers of Uber customers due to what the Information Comissioners’ Officer (ICO) described as “avoidable data security flaws”.
The details of drivers were also taken, including journeys made and how much they were paid. In addition to the ICO’s fine, Holland’s data regulators have fined Uber 600,000 euros (£532,000) over the same incident, as it also affected 174,000 Dutch customers. In the US, it paid out $161.9m (£113 million) to settle federal charges over the same incident.
Uber Put the Victims at Risk of Fraud
Steve Eckersley, director of investigations at the ICO, said: “This was not only a serious failure of data security on Uber’s part but a complete disregard for the customers and drivers whose personal information was stolen.
“At the time, no steps were taken to inform anyone affected by the breach, or to offer help and support. That left them vulnerable. Paying the attackers and then keeping quiet about it afterwards was not, in our view, an appropriate response to the cyber attack.
“Although there was no legal duty to report data breaches under the old legislation, Uber’s poor data protection practices and subsequent decisions and conduct were likely to have compounded the distress of those affected.”
According to sources close to the Wall Street Journal, the company’s CEO Dara Khosrowshahi had known about the data breach more than two months before the public.
In response, Uber said it has changed its data handling procedures since 2016 and hired a chief privacy officer and a data protection head who oversaw its operations.
The company added: “We’ve made a number of technical improvements to the security of our systems both in the immediate wake of the incident as well as in the years since. We’re pleased to close this chapter on the data incident from 2016.”






