UBER TECHNOLOGIES, INC.
ent_019e230eff21c7c21eb6b51af355251c
Disclosures
22
State AG · 9 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
600,000
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- UBER TECHNOLOGIES, INC.
- Normalized
- uber technologies— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300B2FTG34FILDR98
- SEC EDGAR CIK
- 0001543151
- Domain
- None on record
Disclosure history (22)newest first
- Massachusetts State AGas victim2024-08-23
Uber Technologies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-08-23. 1 Massachusetts residents were affected.
- Indiana State AGas victim2024-08-07
Uber Technologies Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-02-13 and was reported on 2024-08-07. 1 Indiana residents were affected. 41 individuals affected in total.
- New Hampshire State AGas victim2023-04-03
Uber Technologies, Inc. reported a data breach where an unauthorized third party accessed systems and exfiltrated driver data between Jan 23-31, 2023. Genova Burns, Uber's legal counsel, detected suspicious activity on Jan 31, 2023. Impacted data included names, SSNs, DOBs, and addresses. Uber engaged forensic specialists, changed passwords, notified law enforcement, and offered 12 months of identity monitoring.
- Maine State AGas victim2023-03-31
Uber Technologies, Inc. reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on January 23, 2023. The breach was discovered on March 2, 2023. The incident affected 10 Maine residents, compromising their names and Social Security numbers. Uber offered 12 months of credit monitoring and identity protection services through Kroll.
- Indiana State AGas victim2023-03-31
Uber Technologies Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-01-23 and was reported on 2023-03-31. 22 Indiana residents were affected. 72,000 individuals affected in total.
- Montana State AGas victim2023-03-31
Genova Burns LLC notified Uber Technologies, Inc. drivers in Montana of a data breach. Unauthorized access occurred Jan 23-31, 2023, affecting names and SSNs/TINs. Genova Burns engaged forensic specialists, secured systems, notified law enforcement, and offered 12 months of Kroll identity monitoring.
- Massachusetts State AGas victim2023-03-31
Uber Technologies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-03-31. 131 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2020-01-01
UBER TECHNOLOGIES filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-004). The register records the breach as discovered on March 22, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2019-10-28
Uber Technologies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-10-28. 65 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2018-12-06
Uber Technologies Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-06. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2017-12-18
Supplemental notice to New Hampshire AG regarding Uber Technologies, Inc. breach affecting 763 NH drivers and 78 US drivers. Notification sent via mail and email.
- Massachusetts State AGas victim2017-11-28
Uber Technologies, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-11-28. 24,149 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2017-11-21
Uber Technologies, Inc. notified the NH AG of a 2016 data breach where unauthorized actors accessed Uber's AWS environment using compromised credentials. The incident affected approximately 600,000 US drivers, exposing names and driver's license numbers. Access occurred Oct 13-Nov 15, 2016. Uber discovered the breach in Nov 2016 but delayed notification until Nov 2017, offering 12 months of credit monitoring.
- Montana State AGas victim2017-11-21
Uber reported a data breach to the Montana Attorney General. The breach was reported on 2017-11-21. The breach occurred from 10/13/2016 to 11/15/2016. 81 Montana residents were affected.
- Oregon State AGas victim2017-11-21
Uber Technologies, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-11-21. The breach occurred during 10/13/2016 - 11/15/2016. The breach was discovered on 11/14/2016. 600,000 individuals were affected. Notice was sent on 11/22/2017.
- Washington State AGas victim2017-11-21
Uber Technologies, Inc. reported a 2016 cyberattack where unauthorized actors accessed Uber's AWS environment using compromised credentials. The incident exposed names and driver's license numbers of approximately 600,000 US drivers, including 10,888 in Washington. Access occurred from Oct 13 to Nov 15, 2016. Uber discovered the breach on Nov 15, 2016, but delayed notification until Nov 22, 2017, offering credit monitoring to affected drivers.
- California State AGas victim2017-11-21
Uber Technologies, Inc. notified the California Attorney General that unauthorized actors accessed private cloud storage containing user information, including names and driver's license numbers, for approximately 600,000 US drivers. The access occurred between October 13 and November 15, 2016. Uber offered 12 months of credit monitoring via Experian.
- Washington State AGas victim2016-06-16
Uber Technologies filed a supplemental notice with the Washington AG regarding unauthorized access to a proprietary database. Access occurred on May 13, 2014, using valid credentials. The breach was discovered in September 2014, but additional driver data (names, driver's license numbers) was identified in May 2016. 1,355 Washington residents were notified in June 2016. Credit monitoring was offered.
- Montana State AGas victim2016-06-15
Uber notified Montana residents of a 2014 data breach where an unauthorized third party accessed a database containing driver names and driver's license numbers. The breach occurred on May 13, 2014, but was discovered in September 2014. Notification was sent in June 2016, offering one year of credit monitoring.
- Massachusetts State AGas victim2015-03-04
Uber Technologies reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-03-04. 4,917 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2015-02-27
Uber Technologies, Inc. disclosed that an unauthorized third party accessed a database containing driver partner information on May 13, 2014. The access was possible due to information being available without intended access restrictions (misconfiguration). Uber discovered the issue in September 2014 and restricted access immediately. In May 2016, after extensive analysis, Uber determined that specific driver partners' names, driver's license numbers, and Social Security numbers were in the accessed database. Notices were sent in June 2016 offering one year of credit monitoring.
- New Hampshire State AGas victim2015-02-26
Uber Technologies, Inc. notified the NH Attorney General of a security breach affecting 15 NH residents. Unauthorized access occurred on May 13, 2014, involving names and driver's license numbers. Uber discovered the vulnerability in September 2014, secured the database, and offered credit monitoring.