Uber Used $100K Bug Bounty to Pay, Silence Florida Hacker: ReportUber Used $100K Bug Bounty to Pay, Silence Florida Hacker: Report
Uber also performed a forensic analysis of the man's computer to ensure he had deleted the stolen information, Reuters said.
December 7, 2017
Uber reportedly paid a 20-year-old Florida man behind its massive data breach $100,000 from its bug bounty program to keep mum about the cyberattack and to delete the stolen data.
A Reuters report quotes unnamed sources familiar with the breach event as saying that Uber paid the man in order to confirm his identity, and had him sign a nondisclosure agreement to prevent him from doing any further damage. Uber also performed a forensic investigation on the man's computer to ensure he had deleted the stolen information.
The man reportedly paid another individual to steal Uber credentials from GitHub, which ultimately led to the Uber systems breach. According to a source quoted in the Reuters report, the man was "living with his mom in a small home trying to help pay the bills."
Uber's use of a bug bounty for the payment was an unusual move: bug bounty payments normally range from $5,000 to $10,000.
See Reuters' full article here.
About the Author(s)
You May Also Like
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
What's In Your Cloud?Nov 30, 2023
Everything You Need to Know About DNS AttacksNov 30, 2023
Passwords Are Passe: Next Gen Authentication Addresses Today's Threats
How to Deploy Zero Trust for Remote Workforce Security
Concerns Mount Over Ransomware, Zero-Day Bugs, and AI-Enabled Malware
Everything You Need to Know About DNS Attacks
Securing the Remote Worker: How to Mitigate Off-Site Cyberattacks
9 Traits You Need to Succeed as a Cybersecurity Leader
The Ultimate Guide to the CISSP
The Burnout Breach: How employee burnout is emerging as the next frontier in cybersecurity
AI in Cybersecurity: Using artificial intelligence to mitigate emerging security risks
Selling Breaches: The Transfer of Enterprise Network Access on Criminal Forums