Uber fined RM2.1m over 2016 cyber attack

By BLOOMBERG

LONDON • Uber Technologies Inc, which is already facing a range of legal and regulatory headaches in London, got another yesterday after it was fined £385,000 (RM2.06 million) over a cyber attack that compromised the data of millions of customers and tens of thousands of drivers.

The Information Commissioner’s Office (ICO) said the personal details of about 2.7 million Uber’s UK customers — including email addresses and phone numbers — may have been downloaded during a 2016 hack. Clients weren’t told for more than a year and the company paid the hackers US$100,000 to destroy the data. In addition, information about 82,000 drivers was exposed.

“This was not only a serious failure of data security on Uber’s part, but a complete disregard for the customers and drivers whose personal information was stolen,” Steve Eckersley, the ICO’s director of investigations, said in a statement. “At the time, no steps were taken to inform anyone affected by the breach, or to offer help and support. That left them vulnerable.”

The fine comes as Uber battles London drivers over their employment status and the number of benefits they are entitled. It was only in June that the ride-sharing company was given a new 15-month probationary licence to operate in the UK capital after transport regulators raised concerns about its gung-ho attitude and the safety of passengers.

Uber said it’s made changes in technology and leadership since the incident.

“Earlier this year, we hired our first chief privacy officer, data protection officer, and a new chief trust and security officer,” the San Francisco-based company said in a statement. “We learn from our mistakes and continue our commitment to earn the trust of our users every day.”