Saturday, 18 Apr 2026

Current affairs publication that encourages citizens’ journalism

Explore Now
Townpress Newspaper
  • News
  • Africa
  • World
  • Business
  • Sports
  • Lifestyle
  • People
  • Motoring
  • Podcast
My News
  • ANC
  • Cyril Ramaphosa
  • eskom
  • facebook
  • twitter
  • SAPS
  • President Cyril Ramaphosa
  • Gauteng
  • DA
  • Nigeria
Townpress NewspaperTownpress Newspaper
Font ResizerAa
  • News
  • Africa
  • World
  • Business
  • Sports
  • Lifestyle
  • People
  • Motoring
  • Podcast
Search
  • News
  • Africa
  • World
  • Business
  • Sports
  • Lifestyle
  • People
  • Motoring
  • Podcast
Have an existing account? Sign In
Follow US
© 2014 - 2026 Townpress Newspaper, South Africa - Townpress logo & associated media rights are the intellectual property of Townpress Newspaper. All Rights Reserved.
Technology

20-year-old paid to keep data breach secret – Uber

Town Press
Last updated: December 7, 2017 4:29 pm
By
Town Press
December 7, 2017
Share
8 Min Read
SHARE

SAN FRANCISCO/WASHINGTON – A 20-year-old Florida man was responsible for the large data breach at Uber Technologies Inc [UBER.UL] last year and was paid by Uber to destroy the data through a so-called “bug bounty” program normally used to identify small code vulnerabilities, three people familiar with the events have told Reuters.

Uber announced on Nov. 21 that the personal data of 57 million users, including 600,000 drivers in the United States, were stolen in a breach that occurred in October 2016, and that it paid the hacker $100,000 (R 1 356 170.00) to destroy the information. But the company did not reveal any information about the hacker or how it paid him the money.

Uber made the payment last year through a program designed to reward security researchers who report flaws in a company’s software, these people said. Uber’s bug bounty service – as such a program is known in the industry – is hosted by a company called HackerOne, which offers its platform to a number of tech companies.

The identity is unable to be establish of the hacker or another person who sources said helped him. Uber spokesman Matt Kallman declined to comment on the matter.

Newly appointed Uber Chief Executive Dara Khosrowshahi fired two of Uber’s top security officials when he announced the breach last month, saying the incident should have been disclosed to regulators at the time it was discovered, about a year before.

It remains unclear who made the final decision to authorize the payment to the hacker and to keep the breach secret, though the sources said then-CEO Travis Kalanick was aware of the breach and bug bounty payment in November of last year.

Block Axes 40% of Staff as AI Strategy Reshapes the Company
Google parts with Cloud VP after uproar over manifesto
Facebook to launch cross platform chats
Microsoft and Qcells on curbing carbon emissions

Kalanick, who stepped down as Uber CEO in June, declined to comment on the matter, according to his spokesman.

A payment of $100,000 (R 1 356 170.00) through a bug bounty program would be extremely unusual, with one former HackerOne executive saying it would represent an “all-time record.” Security professionals said rewarding a hacker who had stolen data also would be well outside the normal rules of a bounty program, where payments are typically in the $5,000 (R67 811.25) to $10,000 (R135 617.00) range.

HackerOne hosts Uber’s bug bounty program but does not manage it, and plays no role in deciding whether payouts are appropriate or how large they should be.

- Advertisement -
Ad image
 Read more: Uber paid hackers to cover up massive data breach

HackerOne CEO Marten Mickos said he could not discuss an individual customer’s programs. “In all cases when a bug bounty award is processed through HackerOne, we receive identifying information of the recipient in the form of an IRS W-9 or W-8BEN form before payment of the award can be made,” he said, referring to U.S. Internal Revenue Service forms.

Read more: Uber bullish on Africa despite opposition from local taxi firms

According to two of the sources, Uber made the payment to confirm the hacker’s identity and have him sign a nondisclosure agreement to deter further wrongdoing. Uber also conducted a forensic analysis of the hacker’s machine to make sure the data had been purged, the sources said.

One source described the hacker as “living with his mom in a small home trying to help pay the bills,” adding that members of Uber’s security team did not want to pursue prosecution of an individual who did not appear to pose a further threat.

The Florida hacker paid a second person for services that involved accessing GitHub, a site widely used by programmers to store their code, to obtain credentials for access to Uber data stored elsewhere, one of the sources said.

GitHub said the attack did not involve a failure of its security systems. “Our recommendation is to never store access tokens, passwords, or other authentication or encryption keys in the code,” that company said in a statement.

Read more: Three Uber security manager resign after CEO criticizes

‘SHOUT IT FROM THE ROOFTOPS’

Uber received an email last year from an anonymous person demanding money in exchange for user data, and the message was forwarded to the company’s bug bounty team in what was described as Uber’s routine practice for such solicitations, according to three sources familiar with the matter.

Bug bounty programs are designed mainly to give security researchers an incentive to report weaknesses they uncover in a company’s software. But complicated scenarios can emerge when dealing with hackers who obtain information illegally or seek a ransom.

Some companies choose not to report more aggressive intrusions to authorities on the grounds that it can be easier and more effective to negotiate directly with hackers in order to limit any harm to customers.

Uber’s $100,000 (R 1 356 170.00) payout and silence on the matter at the time was extraordinary under such a program, according to Luta Security founder Katie Moussouris, a former HackerOne executive.

“If it had been a legitimate bug bounty, it would have been ideal for everyone involved to shout it from the rooftops,” Moussouris said.

Uber’s failure to report the breach to regulators, even though it may have felt it had dealt with the problem, was an error, according to people inside and outside the company who spoke to Reuters.

“The creation of a bug bounty program doesn’t allow Uber, their bounty service provider, or any other company the ability to decide that breach notification laws don’t apply to them,” Moussouris said.

Uber fired its chief security officer, Joe Sullivan, and a deputy, attorney Craig Clark, over their roles in the incident.

“None of this should have happened, and I will not make excuses for it,” Khosrowshahi, said in a blog post announcing the hack last month.

 Clark worked directly for Sullivan but also reported to Uber’s legal and privacy team, according to three people familiar with the arrangement. It is unclear whether Clark informed Uber’s legal department, which typically handled disclosure issues.

Sullivan and Clark did not respond to requests for comment.

In an August, Sullivan a former prosecutor and Facebook Inc (FB.O) security chief, said he integrated security engineers and developers at Uber “with our lawyers and our public policy team who know what regulators care about.”

Last week, three more top managers in Uber’s security unit resigned. One of them, physical security chief Jeff Jones, later told others he would have left anyway, sources told Reuters. Another of the three, senior security engineer Prithvi Rai, later agreed to stay in a new role.

(The story is refiled to correct to 57 million users in second paragraph, showing figure is for both passengers and drivers.)

Facebook Comments

.
  • Case Against Mugabe’s Son And Co-Accused Postponed
  • SASSA Cracks Down On Illegal Sale Of Queue Spots
  • Madlanga Commission: Tshwane CFO To Face Questions Over ‘Fake Municipality’ Tender Scheme
  • Batohi Denied Legal Consultation During Cross-Examination
TAGGED:CEO Marten MickosCraig ClarkHackOneJoe SullivanMatt KallmanUber
Share This Article
Email Copy Link Print
ByTown Press
Follow:
At Town Press, we believe that everyone with a story deserves to be heard. We’re building a dynamic, citizen-led journalism platform that makes news publishing accessible to all South Africans, from rural townships to urban centers, and from first-time voices to seasoned storytellers.
Previous Article Coalition talks in German
Next Article ANC will have successful transition, says Zuma
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Newsletter Subscription

Subscribe to our newsletter to get our newest articles instantly!

    FacebookLike
    XFollow
    YoutubeSubscribe
    MediumFollow
    RSS FeedFollow

    Top News

    Courts

    Case Against Mugabe’s Son And Co-Accused Postponed

    April 17, 2026
    General news

    SASSA Cracks Down On Illegal Sale Of Queue Spots

    April 17, 2026
    Courts

    Madlanga Commission: Tshwane CFO To Face Questions Over ‘Fake Municipality’ Tender Scheme

    April 17, 2026
    Courts

    Batohi Denied Legal Consultation During Cross-Examination

    April 17, 2026
    Top News
    Police appeal for help to find missing couple
    Community
    Illicit Alcohol Under Scrutiny as Compliance Checks Intensify
    Community
    Henke Pistorius Breaks Silence on Son’s Character and New Venture
    Right now
    Malema Returns To Court As Prosecutors Push For Maximum Sentence
    Courts
    Three Bodies, One Grave: Ncumisa Selani’s Secret Murders Shocked Pretoria
    Community
    Private School Shock: King David Victory Park Closure Resurfaces in 2026
    Community

    You May also Like

    Technology

    Initiative to look at affordable data prices

    June 20, 2017
    Technology

    AI Generated War Video Raises Concerns Over Spread Of Digital Misinformation

    March 20, 2026
    CommunityTechnology

    UKZN Unveils New Aerospace Manufacturing Hub

    November 14, 2025
    CommunityPublic Statement

    Berost Randsomeware Attackers hit South Africa

    May 8, 2019
    Show More
    • More News:
    • ANC
    • Cyril Ramaphosa
    • eskom
    • facebook
    • twitter
    • SAPS
    • President Cyril Ramaphosa
    • Gauteng
    • DA
    • Nigeria
    • Johannesburg
    • South Africa
    • zimbabwe
    • jacob zuma
    • EFF
    • Covid-19
    • KwaZulu-Natal
    • State capture
    • cape town
    • Hawks
    Townpress Newspaper

    Indigenous Newspaper created to embolden the township ideals of sharing information and connecting people to grassroots content locally and around the world. We believe communal stories are relevant, so we created the platform to tell the stories of real south africans, people you know.

    Facebook X-twitter Linkedin Youtube Medium Rss

    About Company

    • Contact Us
    • Advertise with US
    • Privacy Policy – T&C
    • Cookie Policy
    • Comments Policy
    • Submit a Tip
    Subscribe Now for Real-time Updates on the Latest Stories!
    © 2014 - 2026 Townpress Newspaper, South Africa - Townpress logo & associated media rights are the intellectual property of Townpress Newspaper. All Rights Reserved
    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    Welcome to Townpress
    Username or Email Address
    Password

    Lost your password?