Attacks/Breaches

4/12/2018
01:20 PM
50%
50%

Uber Agrees to New FTC Settlement Over 2016 Breach Disclosure

Uber has agreed to an updated settlement with the FTC after news of its massive 2016 data breach.

Uber has agreed to an expanded settlement with the Federal Trade Commission, which last year charged the ride-sharing company for deceiving customers with its privacy and data security practices. The new settlement takes into account Uber's massive 2016 data breach.

In the original settlement, proposed in August 2017, the FTC reported Uber failed to live up to claims that it closely monitored employees' access to rider and driver data, and that it implemented measures to secure personal data on third-party cloud servers.

The FTC later learned Uber had failed to disclose a significant breach of user data that occurred in 2016 while it was investigating this settlement. As a result, it has updated its complaint to note that Uber knew about the 2016 breach and paid the attackers $100,000 through a "bug bounty program" to keep quiet. The breach was disclosed a year after it occurred, in Nov. 2017.

In the new agreement, Uber is compelled to disclose future incidents involving consumer data and submit all reports from required third-party audits of its privacy program. It must retain certain records related to bug bounty reports of flaws that could compromise users' data. Uber could be subject to civil penalties if fails to share future incidents with the FTC.

Read more details here.

Interop ITX 2018

Join Dark Reading LIVE for two cybersecurity summits at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the security track here. Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6507
PUBLISHED: 2019-01-22
An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2019-6508
PUBLISHED: 2019-01-22
An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2019-6509
PUBLISHED: 2019-01-22
An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2019-6510
PUBLISHED: 2019-01-22
An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSRF.
CVE-2017-6922
PUBLISHED: 2019-01-22
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not pr...