HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCriticalContained
UBER TECHNOLOGIES, INC.
bd_dfe6822f4d088126 · schema v1 · pii pii-v1
Full breach record for UBER TECHNOLOGIES, INC. →Uber Technologies, Inc. notified the California Attorney General that unauthorized actors accessed private cloud storage containing user information, including names and driver's license numbers, for approximately 600,000 US drivers. The access occurred between October 13 and November 15, 2016. Uber offered 12 months of credit monitoring via Experian.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_74ccb250c0dca8c3Montana State AGfiled 2017-11-21Verified
- bd_8cb0530a7d7281d1Oregon State AGfiled 2017-11-21Candidate
- bd_cb676ca7c713e68bWashington State AGfiled 2017-11-21Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-112414
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 21, 2017
- Raw hash
- f1e61cbfe36233592ca63e013fda857c7e817eda7bd78eecf8eb9167ce120c5d
Reporting entity
- Name
- UBER TECHNOLOGIES, INC.norm: uber technologies
- Domain
- uber.com
Victim entity
- Name
- UBER TECHNOLOGIES, INC.norm: uber technologies
- Domain
- uber.com
Incident
- Discovered
- Nov 1, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 600,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- External
Compliance
- Time to disclose
- 13 months(385 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.