Site icon The Punching Bag Post

Uber Caught Trying to Hide Massive Data Breach

<p class&equals;"MsoNormal" style&equals;"text-align&colon; left&semi;" align&equals;"center">The technology and logistics company&comma; Uber has been caught attempting to conceal an October 2016 data breach that exposed 57 million peoples&rsquo&semi; personal information&period;<&sol;p>&NewLine;<p class&equals;"MsoNormal">First reported by <em style&equals;"mso-bidi-font-style&colon; normal&semi;">Bloomberg<&sol;em>&comma; the company paid 100&comma;000 to two hackers after they stole the company&rsquo&semi;s customer data in exchange for their silence and the deletion of the stolen information&period; &nbsp&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;A big part of the shock and disappointment comes from the fact that Uber appears to have paid hush money to keep this under wraps&comma;&rdquo&semi; said Kowsik Guruswamy&comma; chief technology officer at Menlo Security to <em style&equals;"mso-bidi-font-style&colon; normal&semi;">Financial Times&period;<&sol;em><em style&equals;"mso-bidi-font-style&colon; normal&semi;">&nbsp&semi;<&sol;em><&sol;p>&NewLine;<p class&equals;"MsoNormal">Although the Federal Bureau doesn&rsquo&semi;t recommend that a company pay hackers in these types of case&comma; it still has happened before&period;<&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;The most high-profile example was when Hollywood Presbyterian Medical Center paid a &dollar;17&comma;000 ransom in bitcoin last year to hackers who seized control of the hospital&rsquo&semi;s computer systems&comma;&rdquo&semi; writes <em style&equals;"mso-bidi-font-style&colon; normal&semi;">Financial Times&period;<&sol;em>&nbsp&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal">The personal information stolen included names&comma; email addresses and phone numbers of both the Uber customers and the drivers&period; 600&comma;000 U&period;S&period; drivers&rsquo&semi; license plate numbers were also taken in the breach&period;<span style&equals;"mso-spacerun&colon; yes&semi;">&nbsp&semi;&nbsp&semi; <&sol;span><&sol;p>&NewLine;<p class&equals;"MsoNormal">Unlike the recent massive Equifax cyber hack&comma; no credit card information&comma; along with customers&rsquo&semi; trip histories were included in the breach&period;<&sol;p>&NewLine;<p class&equals;"MsoNormal">When the company discovered the breach back in December of 2016&comma; Uber decided to not notify regulators or the people comprised in the hack&period; On Tuesday&comma; Uber finally acknowledged the breach&period; &nbsp&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal">Dara Khosrowshahi&comma; who became Uber&rsquo&semi;s chief executive in September&comma; said that once he heard about the breach&comma; he ordered an investigation&period; &nbsp&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;At the time of the incident&comma; we took immediate steps to secure the data and shut down further unauthorized access by the individuals&comma;&rdquo&semi; said Khosrowshahi&period; &ldquo&semi;We subsequently identified the individuals and obtained assurances that the downloaded data had been destroyed&period; We also implemented security measures to restrict access to and strengthen controls on our cloud-based storage accounts&period;&rdquo&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal"><span style&equals;"mso-fareast-font-family&colon; 'Times New Roman'&semi;">However&comma; these steps did not include alerting the individuals who were affected&period;<&sol;span><&sol;p>&NewLine;<p class&equals;"MsoNormal">Khosrowshahi has also asked for Sullivan&comma; Uber&rsquo&semi;s chief security officer&rsquo&semi;s resignation&comma; along with the lawyer that reported to him&period;<&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;None of this should have happened&comma; and I will not make excuses for it&comma;&rdquo&semi; said Khosrowshahi&period;<&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;While I can&rsquo&semi;t erase the past&comma; I can commit on behalf of every Uber employee that we will learn from our mistakes&period; We are changing the way we do business&period;&rdquo&semi;&nbsp&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal">It&rsquo&semi;s safe to say that Khosrowshahi has a rocky road ahead of him&period;&nbsp&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;The latest news about the data breach is just one of many legacy bad decisions that Khosrowshahi has had to inherit since Kalanick was ousted from the company in June&period; The company is facing several other federal investigations into its business practices and is preparing to stand trial against accusations of trade secret misappropriation by its rival Waymo next month&comma;&rdquo&semi; writes <em style&equals;"mso-bidi-font-style&colon; normal&semi;">Forbes&period;<&sol;em><&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;Mr&period; Khosrowshahi&rsquo&semi;s decision to publicly announce the data breach &mdash&semi; during a holiday week as the US celebrates Thanksgiving &mdash&semi; represents an effort to get skeletons out of the closet during the first months of his tenure&comma;&rdquo&semi; writes <em style&equals;"mso-bidi-font-style&colon; normal&semi;">Financial Times&period; <&sol;em>&nbsp&semi;<&sol;p>&NewLine;<p class&equals;"MsoNormal">Apparently&comma; trying to hide cyber breaches at companies is more common than you think&period;<&sol;p>&NewLine;<p class&equals;"MsoNormal">&ldquo&semi;Developers make mistakes on the cloud infrastructure&comma; and hackers take advantage of that&comma;&rdquo&semi; said Kobi Ben-Naim&comma; the head of the cyber research lab at CyberArk to the <em style&equals;"mso-bidi-font-style&colon; normal&semi;">Times of Israel&period;<&sol;em><&sol;p>&NewLine;<p class&equals;"MsoNormal"><strong>Author&rsquo&semi;s note&colon; <&sol;strong>This is another example of how irresponsible a technology company can be&period; Uber should have alerted those affected as soon as possible&comma; instead of waiting a WHOLE year&period; Now the company&rsquo&semi;s PR nightmare is going to be even worse because Uber executives tried to hide it from their employees and customers&period;<&sol;p>&NewLine;<p class&equals;"MsoNormal"><strong>Editor&&num;8217&semi;s note&colon;<&sol;strong> Our privacy is under attack&comma; no one seems to care the damage it does to the victims&period;<&sol;p>&NewLine;<p>&nbsp&semi;<&sol;p>&NewLine;

Exit mobile version