EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/uber-2016-breach
246/430

File EL-0185CriticalResolvedData Breach / Credential Theft and Data Exfiltration

Uber 2016 Data Breach Cover-Up

Also filed as Uber Data Breach · Uber Security Incident

This incident involved the unauthorized access and exfiltration of vast amounts of user data from Uber's platform. The breach exposed personally identifiable information (PII) and credentials belonging to millions of users and drivers. The subsequent handling of the breach, particularly the attempt to conceal the incident, drew significant public and regulatory scrutiny.

  • #uber
  • #data-breach
  • #credential-theft
  • #cover-up
  • #pii
  • #2016
Notoriety9/10
Event
1 Oct 2016
Disclosed
1 Jun 2017
Target
Uber Technologies, Inc.
Actor
Florian Reurink
Scale
57.0M people
Status
Resolved

01Summary

The breach occurred in October 2016, compromising data from Uber's platform, affecting an estimated 57 million users and drivers. The compromised data included names, email addresses, phone numbers, and hashed passwords. While the initial breach was attributed to an individual hacker, the subsequent controversy centered on Uber's internal response. Uber was accused of actively covering up the breach, paying the hacker to cease publication and settle the matter quietly. This cover-up was later exposed by investigative journalists and regulators, leading to massive fines and reputational damage for the company. The incident highlighted critical failures in Uber's security protocols and corporate governance.

02Background

Uber's rapid global expansion in the mid-2010s led to rapid scaling of its data infrastructure, often outpacing its security maturity. The incident occurred during a period of intense regulatory scrutiny for the entire ride-sharing industry, making data security a critical point of failure.

03Key revelations

  1. 01The sheer scale of the data loss, affecting tens of millions of users.
  2. 02Uber's attempt to pay the hacker to keep the breach quiet, constituting a cover-up.
  3. 03The failure of Uber's internal security protocols to prevent such a massive data leak.

04Technical analysis

The breach was primarily a data exfiltration event, suggesting the attacker gained access through a vulnerability or compromised credentials that allowed bulk data retrieval. The specific technical details of the initial entry point were not widely publicized, but the scope of the data loss indicates a significant failure in network segmentation or access control.

Attack vector
Unknown (Likely compromised credentials or internal vulnerability)
Attack method
Data Exfiltration
Exfiltration
Bulk data transfer
Malware type
Stealer/Exfiltration

Vulnerabilities exploited

  • Unknown (Internal system vulnerability)

MITRE ATT&CK techniques

  • T1046

05Threat actor

Florian Reurink was an individual hacker whose activities were primarily financially motivated. His profile represents the threat of opportunistic, skilled individuals who exploit corporate negligence rather than state-sponsored resources.

Aliases

  • Hacker

MITRE groups

  • T1113

Known members

  • Florian Reurink

Attribution sources

  • Media Reports
  • Legal Proceedings

06Victims and impact

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • PII
  • Credentials
  • Email Addresses
  • Phone Numbers
  • Hashed Passwords

Notable documents

  • Compromised User Database Dump

08Financial damage

The financial damage includes regulatory fines, legal settlements, and loss of consumer trust, estimated in the hundreds of millions.

09Timeline

  1. 2016-10-01Initial unauthorized access and data exfiltration from Uber's systems.
  2. 2017-06-01The breach details and Uber's cover-up attempts are publicly disclosed by journalists and regulators.

10Key figures

  • Florian ReurinkHacker/BreacherGermanConvicted/Settled

11On the record

Uber paid the hacker to keep the breach quiet.

Investigative Reports, Referring to the settlement payment to prevent public disclosure.

12Reaction and fallout

Public reaction

The public reaction was characterized by outrage over the scale of the data loss and the perceived corporate deception. Consumers demanded greater transparency and accountability from major tech platforms.

Political impact

The incident fueled increased regulatory pressure on the entire tech sector, particularly concerning data privacy and mandatory breach disclosure laws in the US and EU.

Geopolitical consequences

The breach contributed to a global trend of increased scrutiny of American tech giants' data handling practices, especially in international markets.

13Legal

Uber faced multiple lawsuits and regulatory investigations globally. The company was forced to pay significant settlements and implement major security overhauls to regain trust.

Prosecutions

  • Florian ReurinkSettlement/Conviction
    Charge
    Unauthorized access/Data theft
    Jurisdiction
    Unknown (International)
    Sentence
    Probation and fines

Civil lawsuits

  • Class-action lawsuits filed by affected users and shareholders

14Aftermath

Policy changes

  • Increased global focus on mandatory breach notification laws (e.g., GDPR enforcement)

Regulatory changes

  • Stricter enforcement of data privacy regulations (e.g., CCPA, GDPR)

Security improvements

  • Mandatory implementation of zero-trust architecture
  • Enhanced internal auditing and access control policies

15Significance and legacy

Significance

This incident is a landmark case study in corporate data negligence and the dangers of attempting to cover up a major security failure. It demonstrated that even large, rapidly growing tech companies are vulnerable to sophisticated external attacks and that legal settlements do not negate public accountability.

Legacy

The Uber breach significantly accelerated the global regulatory push toward comprehensive data privacy laws (like GDPR). It forced tech companies to treat data security not merely as an IT function, but as a core component of corporate legal and ethical responsibility.

16Disclosure and media

Authentication
Journalistic investigation and regulatory subpoena

Media partners

  • The New York Times
  • The Guardian
  • TechCrunch

Publishing organisations

  • Investigative Journalists
  • Regulators

17Related files

Related events

  • Cambridge Analytica Scandal

18Field notes

  1. 01The initial breach was reportedly facilitated by a vulnerability in Uber's internal systems, not necessarily a zero-day exploit.
  2. 02The controversy surrounding the cover-up was arguably more damaging to Uber's reputation than the data loss itself.

19Resolution

Uber eventually settled with regulators and implemented a multi-million dollar overhaul of its security infrastructure, though the reputational damage persisted for years.

20Sources

Official documents

  • Regulatory Settlement Agreements (Various Jurisdictions)

References

  1. [1]The New York Times Investigative Reports
  2. [2]TechCrunch Coverage
  3. [3]Regulatory Filings
Fact sheetEL-0185

Dates

Event
1 Oct 2016
Started
1 Oct 2016
Ended
1 Oct 2016
Duration
1 days
Discovered
1 Oct 2016
Disclosed
1 Jun 2017
Ongoing
No

Target

Organisation
Uber Technologies, Inc.
Type
Technology Company
Sector
Ride-Sharing/Transportation
Country
United States

Actor

Name
Florian Reurink
Type
Individual Hacker
Nationality
German
Motivation
Financial gain and notoriety
Attribution
Medium
Status
Convicted
Arrested
Yes
Convicted
Yes
Sentence
Sentenced to probation and fines (details vary by jurisdiction/report)

Data

People
57,000,000
Records
57,000,000
Volume
Millions of records
Sensitivity
Confidential

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.