HackingStolen CredentialsDelayed DiscoveryData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTPIIMediumContained
UBER TECHNOLOGIES, INC.
bd_5994ff85006d8e3f · schema v1 · pii pii-v1
Full breach record for UBER TECHNOLOGIES, INC. →Uber Technologies, Inc. disclosed a 2014 data breach affecting driver partners. An unauthorized third party accessed a database on May 13, 2014, exploiting credentials that lacked intended access restrictions. The breach exposed names, driver's license numbers, and Social Security numbers. Uber discovered the vulnerability in September 2014, restricted access, and notified affected individuals in June 2016, offering credit monitoring.
California clockDiscovered Sep 1, 2014 → Notified Jun 16, 2016654d ✗ CA 60-day late26 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-48540
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 27, 2015
- Raw hash
- 0623a7e84e461b0146ccc322c52c59b0cfa9574c70405edad93d20b2824cef92
Reporting entity
- Name
- UBER TECHNOLOGIES, INC.norm: uber technologies
- Domain
- uber.com
Victim entity
- Name
- UBER TECHNOLOGIES, INC.norm: uber technologies
- Domain
- uber.com
Incident
- Discovered
- Sep 1, 2014
- Materiality determined
- —
- Notification sent
- Jun 16, 2016
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 26 weeks(179 days from discovery to filing)
- Compliance flags
- CA 60-day late · 654d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 1, 2014→ Notified: Jun 16, 2016654d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.