So Uber finally admitted something today that a lot of us suspected was coming eventually, just maybe not quite like this. Dara Khosrowshahi, who's only been CEO for a few months now, put up a blog post this afternoon saying that back in late 2016 hackers got into Uber's systems and pulled data on 57 million riders and drivers. Names, emails, phone numbers, the usual grab bag. But also something worse: roughly 600,000 driver's license numbers belonging to US-based drivers.
Here's the part that actually made me put my coffee down. Uber knew about this over a year ago. Instead of telling anyone, they paid the hackers $100,000 to delete the data and keep quiet about it, and ran it through their bug bounty program like it was just another responsible disclosure payout. It very much was not that. The guy who was Uber's chief security officer at the time is reportedly out because of this. All of it happened on Travis Kalanick's watch, while he was still CEO, and while Uber was simultaneously in the middle of negotiating with the FTC over a completely different 2014 breach. So the company was telling regulators one thing about its security practices while sitting on a much bigger, fresher mess.
I went and checked my own email the second I read this, half expecting some kind of notification. Nothing. Not a word. Which I guess makes sense since the breach note is only going out now, over a year after the fact, but it's a weird feeling knowing your data might've been sitting on some stranger's hard drive since before the 2016 election and you had zero say in the matter. I don't even use Uber that much anymore honestly, I switched back to a local cab company here a while back mostly because the surge pricing thing annoyed me one too many times on a rainy Tuesday, but I still had an account with a saved card on file, which is exactly the kind of thing that makes this stuff matter even for casual users.
The bigger issue, and this is the part that never gets said loud enough, is that this is exactly the situation password reuse turns into a real problem instead of a hypothetical one. If your Uber password is the same one you use for your email or your bank, tonight's the night to go fix that, not next week. I'll admit I'm guilty of reusing passwords for low-stakes stuff too, some throwaway forum login probably still shares a password with something I actually care about, and every time one of these breaches happens I tell myself I'll finally set up a proper password manager and then I don't, until the next breach reminds me again. Classic.
What gets me about the Uber angle specifically, versus just another "company got hacked" story, is the year of silence. Getting hacked happens to everybody eventually, no system is bulletproof, and I don't think that alone makes a company evil or incompetent. But choosing to pay off the people who did it and calling it a bug bounty so it doesn't have to become a headline, that's a decision made by actual humans sitting in a room, weighing the PR cost against just doing the right thing and picking the wrong one. Khosrowshahi's post frames this as him cleaning up a mess he inherited, and to be fair to him he wasn't CEO yet when any of this happened, but "we just found out too" only works as a defense for so long when you're the one now in charge of deciding what else gets disclosed and when.
Driver's license numbers are the detail I keep coming back to. Emails and phone numbers get scraped and traded constantly, it's almost background noise at this point, sad as that is to say. But a driver's license number tied to your real identity is a different category of exposure, and it's not something you can just reset with a password change. If you drove for Uber in the US anytime before late 2016, that number might be out there now, and there isn't really a button you can press to undo that.
Going to go actually delete that saved card off my account tonight. Should've done it months ago for the surge pricing reason alone, this just finally pushed me to do it.