vz-risk / VCDB

VERIS Community Database
Other
573 stars 180 forks source link

Uber Data Breach Exposed Personal Information of 20 Million Users #11263

Open swidup opened 6 years ago

swidup commented 6 years ago

http://fortune.com/2018/04/12/uber-data-breach-security/

swidup commented 6 years ago

In the 2016 breach, intruders in a data-storage service run by Amazon.com Inc. obtained unencrypted consumer personal information relating to U.S. riders and drivers, including 25.6 million names and email addresses, 22.1 million names and mobile phone numbers, and 607,000 names and driver’s license numbers, the FTC said in a complaint.

We don't seem to have this one in the dataset.

swidup commented 6 years ago

https://www.ftc.gov/system/files/documents/cases/1523054_uber_technologies_decision_and_order.pdf

swidup commented 5 years ago

https://ico.org.uk/media/action-weve-taken/mpns/2553890/uber-monetary-penalty-notice-26-november-2018.pdf Much more detail, plus they were fined. Also, affected 32 million not 25.6.

"IOI_regulatory_fines": "Yes", "IOI_regulatory_fines_amt": "385000", "IOI_currency_code": "GDP"

swidup commented 5 years ago

https://news.softpedia.com/news/uber-gets-over-1-million-fine-for-not-telling-clients-watchdogs-of-data-breach-524009.shtml and more fines

Moreover, "The Dutch Data Protection Authority (Dutch DPA) imposes a fine of €600.000 upon Uber B.V. and Uber Technologies, Inc (UTI) for violating the Dutch data breach regulation. In 2016 a data breach occurred at the Uber concern in the form of unauthorised access to personal data of customers and drivers."

"IOI_regulatory_fines": "Yes", "IOI_regulatory_fines_amt": "600000", "IOI_currency_code": "EUR"