Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


04:40 PM
Connect Directly

Uber's Security Slip-ups: What Went Wrong

The ride-sharing company's decisions leading to a 2016 data breach and its handling of the incident should serve as a cautionary tale for enterprises facing a breach.

Uber is digging out from the wreckage of its latest public relations nightmare, an October 2016 data breach that compromised the information of 57 million riders and drivers.

The company has received backlash not for the size of the breach but how it was handled. Instead of informing those affected, Uber paid attackers $100,000 to delete the stolen data and keep their activity quiet. The hack was disclosed last week, a year after Uber found out about it. The attempted cover-up was one of many mistakes leading up to the breach and the subsequent response.

Former CISO Joe Sullivan, who spearheaded incident response, and his deputy have both been fired for mishandling the hack. Current CEO Dara Khosrowshahi, who took charge in September, says Uber "took immediate steps" to secure affected data, shut down further unauthorized access, and "obtained assurances that the downloaded data had been destroyed."

The CEO may be using the 2016 breach as a catalyst in transforming Uber's approach to security. Khosrowshahi says "we will learn from our mistakes" and "we are changing the way we do business." However, experts across industries have criticized Uber's initial response to a hack that compromised millions of users, as well as the basic security slip-ups that let it happen.

Uber is individually notifying drivers whose license numbers were compromised and offering free credit monitoring and identity theft protection, Khosrowshahi reports. It is also alerting regulatory authorities and affected accounts, which have been flagged for fraud protection.

Where Uber Went Wrong

For starters, the company should have immediately come clean. "Uber undoubtedly violated numerous US and international data breach disclosure laws by failing to inform drivers and users that their personal information had been compromised," says ZScaler CISO Michael Sutton. Several state and federal regulations dictate when such disclosures must be made.

The company should also have had stronger access control for such a large collection of data. Attackers initially accessed a private GitHub coding site for Uber software engineers, where they found credentials for an Amazon Web Services account containing users' information.

This wasn't a sophisticated attack, Imperva CTO Terry Ray points out, questioning Uber's decision to use live production data in an online platform where credentials were stored in GitHub. Developers are frequently allowed to use live production data in testing; unfortunately, this information is "almost never monitored or secured" and often stored in various locations.

Ray points out a few questions that should be considered in the wake of the breach:

  • Why did engineers have access to 57 million records of personally identifiable information?
  • Did they go through an approval workflow to move that data online?
  • Did Uber security have any monitoring in place to alert them when such vast amounts of data were accessed?

"Controls to alert on suspicious data access do exist," says Ray. "But my guess is that they were not used, which is all too typical in today’s enterprises."

Snyk cofounder and CEO Guy Podjarny says credentials should not have been in GitHub in the first place, and that one user's credentials should not have given access to so much data at once. All it took was the compromise of one individual to give attackers the keys.

"The fact that developers have access to GitHub repositories, and the fact that there was access to many customers' data, are both instances of preferring ease-of-use over security," he notes. Uber could have mitigated the damage with preventative measures around data downloads. Once information was compromised, it should have identified the volume of downloaded data.

Experts also say Uber should have encrypted its data before storing it with a third-party service. "It's not a GitHub security issue or an AWS security issue," says McAfee Labs vice president Vincent Weafer. "It really comes down to the user, and not system security issues."

While Uber was wrong not to come forward about the hack, there is less certainty around its decision to pay the attackers, who demanded $100K to delete the stolen data. It's ill-advised and often dangerous to pay hackers, a practice that will continue to drive extortion.

Legal Ramifications

Ken Spinner, vice president of field engineering at Varonis, says "every state attorney general is going to be salivating at the prospect of suing Uber." The lawsuits have already begun to roll in: a class-action lawsuit has been filed against Uber by Wilshire Law Firm on behalf of its client, Flores. Complaints allege Uber violated California constitutional laws and unfair competition laws, engaged in deceptive business practices, and invaded privacy, among other violations.

Uber says it has not seen evidence of fraud or misuse related to the breach, according to Khosrowshahi's statement; however, a press release on the aforementioned lawsuit reports the information stolen by hackers has allegedly ended up on the black market while Uber kept mum about the situation.

At the time of writing, Uber has not responded to Dark Reading's request for comment regarding data shared on the black market.

Related Content:

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Strategist
12/14/2017 | 5:20:42 PM
scramble data
Uber should have scrambled the data before it went into the test environment.
User Rank: Apprentice
11/30/2017 | 11:14:16 PM
What went wrong 'after the incident'
Great article Kelly, but what went wrong after the incident?

Understand that it's critical to understand what went wrong to cause the incident, but I feel it would be very insightful to understand who made the decision not to disclose the incident.  

Where did that decision occur?  At Uber's Board, CEO, Legal team.  Even if that decision was left to the CISO then that's actually a damning indictment on their delegation of authority. 

I understand that Uber want to offer up the CISO as the official 'scapegoat' but wow if the standard response to a major data breach is 'sack the CISO' then in not to long we will be faced with an understaffed industry having to fill strategic leadership positions potentially with highly skilled cyber security people that may not have had the training and experience to work at the strategic C suite level.

I 'Hacked' My Accounts Using My Mobile Number: Here's What I Learned
Nicole Sette, Director in the Cyber Risk practice of Kroll, a division of Duff & Phelps,  11/19/2019
6 Top Nontechnical Degrees for Cybersecurity
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/21/2019
TPM-Fail: What It Means & What to Do About It
Ari Singer, CTO at TrustPhi,  11/19/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-11-22
An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to execute arbitrary syste...
PUBLISHED: 2019-11-22
Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. An attacker with physical access to the device can install arbitrary firmware.
PUBLISHED: 2019-11-22
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding...
PUBLISHED: 2019-11-22
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.
PUBLISHED: 2019-11-22
The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for error messages, leading to the ability to inject client-side code.