Form: Cost-of-Breach DisclosureSource: IBM 2025Filed: 28 Apr 2026
DataBreachCost.comOpen calc
Case File 04.UBR / Uber Technologies, Inc.Breached Oct 2016, disclosed Nov 2017

Case ID

Uber 2016: the breach that was paid to disappear.

The theft itself was ordinary: two hackers found a credential in a private code repository and copied 57 million rider and driver records out of Uber's cloud storage. What made it a landmark was the response. Uber paid the attackers $100,000 to delete the data and stay quiet, funnelled the payment through its own bug-bounty program to disguise it as a security reward, and told no one for more than a year. When the concealment surfaced it produced a $148 million settlement with all 50 states, fines from three national regulators, and the first criminal conviction of a corporate security executive over a data breach. The lesson the register keeps is that the cover-up, not the intrusion, is what cost Uber.

Records exposed

57M

50M riders + 7M drivers

50-state settlement

$148M

AGs of all 50 states + DC, Sept 2018

Hush payment

$100K

Bitcoin, routed via HackerOne

CSO conviction

First ever

Joe Sullivan, guilty Oct 2022

Section UBR.1

One leaked credential, 57 million records

In October 2016 two attackers, Brandon Glover of Florida and Vasile Mereacre of Toronto, used a tool that tested leaked username-and-password pairs against corporate systems. They found login credentials for a private Uber GitHub repository used by the company's engineers. Inside that repository were Amazon Web Services access keys. Those keys unlocked an Uber backup stored in AWS S3, and from it the pair downloaded the personal data of roughly 57 million people worldwide.

The exposed records covered about 50 million riders and 7 million drivers. For riders the data was names, email addresses, and mobile phone numbers. For drivers it also included the driver's license numbers of roughly 600,000 US drivers. No payment-card numbers, bank details, dates of birth, or Social Security numbers were in the affected backup. The intrusion was not technically sophisticated. It was a plaintext secret committed to source control, the same class of mistake that later drove the 2019 Capital One and 2024 Snowflake breaches.

Section UBR.2

The $100,000 payment, disguised as a bug bounty

Rather than a vulnerability report, the hackers sent an extortion demand: pay us, or the data goes public. Uber's security team, led by chief security officer Joe Sullivan, agreed to pay $100,000 in Bitcoin. To disguise a ransom as a legitimate expense, the company routed it through HackerOne, the platform that runs its bug-bounty program, a channel meant for rewarding researchers who responsibly disclose flaws. The two attackers were then required to sign non-disclosure agreements that falsely stated they had not taken or stored any data.

Uber did not notify the affected riders and drivers, the Federal Trade Commission, or state regulators. The breach stayed buried for more than a year. It became public only in November 2017, after a new chief executive, Dara Khosrowshahi, learned of it during a post-acquisition review, disclosed it, and fired Sullivan and a deputy. The disguised-payment detail is what turned a data-security failure into a concealment case: paying an attacker is not itself a crime, but paying one through a bug-bounty program to hide a reportable breach is what prosecutors and regulators built their cases around.

Section UBR.3

What the concealment cost

ConsequenceAmountSource
Settlement with the attorneys general of all 50 states + DC$148MCalifornia AG / 50-state settlement, 26 September 2018
UK Information Commissioner's Office fine£385,000ICO monetary penalty notice, 26 November 2018
Dutch Data Protection Authority fine€600,000Autoriteit Persoonsgegevens, November 2018
French CNIL fine€400,000CNIL, December 2018
Payment to the attackers (the hush money)$100,000DOJ non-prosecution agreement, July 2022
FTC settlement (expanded consent order)No fineFTC final order, 25 October 2018: 20 years of biennial privacy assessments

The $148 million paid to the states dwarfs every other line and was, at the time, the largest multi-state data-breach settlement on record. It resolved allegations that Uber violated state breach-notification and reasonable-security laws by hiding the incident. The FTC settlement carried no monetary penalty but imposed two decades of mandatory third-party privacy audits and a requirement to report future breaches, because the 2016 concealment happened while Uber was already under FTC investigation for an earlier 2014 breach. The regulator fines in the UK, Netherlands, and France are small by comparison and reflect that these were pre-GDPR penalties under the older data-protection regimes; a breach of this scale disclosed under GDPR today would face far higher exposure.

Section UBR.4

Ten days after sworn testimony

The obstruction case turned on timing. In 2014 Uber had suffered an earlier, smaller breach, and the FTC opened an investigation into the company's data-security practices. On 15 November 2016 Sullivan gave sworn testimony to the FTC about how Uber protected user data. Roughly ten days later he learned that Uber had just been hacked again, far more seriously. He did not correct or supplement his testimony, and he withheld the new breach from the Uber lawyers who were handling the FTC matter. That withholding, from an active federal investigation, is what the Department of Justice charged as obstruction.

Uber itself avoided prosecution. In July 2022 the company entered a non-prosecution agreement with the DOJ, admitting that its personnel had concealed the 2016 breach from the FTC. The agreement credited Uber's new leadership for disclosing the incident and cooperating once it was discovered, which is precisely the conduct the criminal case against the individual executive punished the absence of.

Section UBR.5

The first security executive convicted over a breach

On 5 October 2022 a federal jury in San Francisco found Joe Sullivan guilty of two felonies: obstruction of an FTC proceeding and misprision of felony, the deliberate concealment of a crime. It was the first time a corporate security executive was criminally convicted for the handling of a data breach, and it sent a signal through the profession that breach concealment is a personal legal risk, not just a corporate one.

On 4 May 2023 he was sentenced to three years of probation, 200 hours of community service, and a $50,000 fine, avoiding the prison term prosecutors had sought. A federal appeals court later upheld the conviction. The two hackers, Glover and Mereacre, had already pleaded guilty in October 2019 to conspiracy to commit extortion, for the Uber breach and a separate intrusion at Lynda.com; each faced up to five years. The through-line the case established is now standard guidance in incident-response playbooks: a breach must be reported, an extortion payment cannot be dressed up as a bug bounty, and the security leader who buries an incident can be the one who goes to court.

Section UBR.6

Why the cover-up was the cost

Uber's 2016 breach exposed no payment-card or medical data, the record types that drive the highest per-record settlements, and the intrusion was contained once the credential was rotated. On the raw exposure alone it would rank as a mid-tier breach. Almost the entire documented cost, the $148 million to the states, the FTC's two-decade monitoring order, and a criminal conviction, flowed from the decision to conceal rather than disclose. It is the clearest case in the register of a concealment premium: notification and regulatory-reporting obligations are cheap to meet on time and ruinously expensive to evade. IBM's annual data-breach research reaches the same conclusion in aggregate, breaches that take longer to identify and contain cost more, and Uber is the extreme worked example, a breach whose real price was set not by the attackers but by the year of silence that followed.

Cross-references

Schedule F / Reference Q&A

Frequently Asked Questions

Primary source:Uber 2016 breach data from the 50-state attorney general settlement announced 26 September 2018, the FTC's expanded consent order (final approval 25 October 2018), the Department of Justice non-prosecution agreement with Uber (July 2022), the DOJ prosecution and 4 May 2023 sentencing of Joseph Sullivan (obstruction of an FTC proceeding and misprision of felony), the October 2019 guilty pleas of Brandon Glover and Vasile Mereacre, the UK ICO monetary penalty notice (26 November 2018), and Uber's SEC filings recording the UK, Dutch, and French regulator fines.