Pennsylvania attorney general sues Uber over 2016 data breach

At least 57 million people were affected.
 By 
Kerry Flynn
 on 
Pennsylvania attorney general sues Uber over 2016 data breach
Your lawsuit is arriving now. Credit: leon neal/getty images

Uber's bad days are far from over. Pennsylvania Attorney General Josh Shapiro sued Uber on Monday for not disclosing a massive data breach for more than a year after it occurred in 2016.

Shapiro's lawsuit alleged that Uber violated Pennsylvania state law by not notifying customers within a "reasonable amount of time," The Hill reported. Shapiro can seek up to $1,000 in fines for every violation.

“Uber violated Pennsylvania law by failing to put our residents on timely notice of this massive data breach,” Shapiro said in a statement, according to The Hill. “Instead of notifying impacted consumers of the breach within a reasonable amount of time, Uber hid the incident for over a year – and actually paid the hackers to delete the data and stay quiet. That’s just outrageous corporate misconduct, and I’m suing to hold them accountable and recover for Pennsylvanians.”

An Uber spokesperson responded: "While we make no excuses for the previous failure to disclose the data breach, Uber's new leadership has taken a series of steps to be accountable and respond responsibly. We investigated the incident, disclosed the circumstances to state and federal regulators, and reached out to state Attorneys General, including Attorney General Shapiro, to express Uber's desire to cooperate fully with any investigations. While we dispute the accuracy of some of the characterizations in the Pennsylvania Attorney General's lawsuit, we will continue to cooperate with them and ask only that we be treated fairly."

Uber had disclosed the hack of 57 million Uber customers and drivers back in November. The data breach leaked the names, email addresses, and phone numbers of about 50 million Uber riders and the personal information of 7 million drivers. It did not include social security numbers or details about the rides, according to Uber's blog post.

At the time of Uber discovering the leak, the company paid the hacker $100,000 to delete the data and to stay quiet. Uber kept the secret under former CEO and cofounder Travis Kalanick. In November, new CEO Dara Khosrowshahi disclosed the occurrence and also fired Uber's Chief Security Officer Joe Sullivan.

“None of this should have happened, and I will not make excuses for it,” Khosrowshahi told Bloomberg in November. “We are changing the way we do business.”

But Shapiro is not letting Uber get away with negligence. According to Shapiro's office, as reported by The Hill, 43 state attorney generals are investigating Uber's 2016 data breach.

Later on Monday, Uber's Chief Legal Officer Tony West released a statement claiming that he had spoken directly with Shapiro last month and was "surprised" by the lawsuit.

"Since starting on this job three months ago, I’ve spoken with various state and federal regulators in connection with the data breach pledging Uber’s cooperation, and I personally reached out to Attorney General Shapiro and his team in the same spirit a few weeks ago. While I was surprised by Pennsylvania’s complaint this morning, I look forward to continuing the dialogue we’ve started as Uber seeks to resolve this matter. We make no excuses for the previous failure to disclose the data breach. While we do not in any way minimize what occurred, it's crucial to note that the information compromised did not include any sensitive consumer information such as credit card numbers or social security numbers, which present a higher risk of harm than driver’s license numbers. I’ve been up front about the fact that Uber expects to be held accountable; our only ask is that Uber be treated fairly and that any penalty reasonably fit the facts," West wrote in an emailed statement.

Updated 3/15/2018, 1:13 p.m. with statement from Uber.

Updated 3/15/2018, 4:06 p.m. with statement from Uber's chief legal officer.

Mashable Image
Kerry Flynn

Kerry Flynn is a business reporter for Mashable covering the tech industry. She previously reported on social media companies, mobile apps and startups for International Business Times. She has also written for The Huffington Post, Forbes and Money magazine. Kerry studied environmental science and economics at Harvard College, where she led The Harvard Crimson's metro news and design teams and played mellophone in the Band. When not listening to startup pitches, she runs half-marathons, plays with puppies and pretends to like craft beer.

Mashable Potato

Recommended For You

Panera Bread breach: ShinyHunters claims hack of 14 million customers' data
Panera Bread logo on storefront

Instagram denies data breach: So what's up with those sketchy change password emails?
instagram logo against a black background

Anthropic sues Pentagon as Claude downloads soar
The Anthropic logo displayed on the stage

Yet another state makes moves to end dynamic pricing
back of woman looking at dairy aisle at grocery store

More in Tech
The Earth is glowing in new Artemis II pictures of home
One half of the Earth is seen floating in space through the open door of the Orion spacecraft.

Doomsday Clock now closest to midnight ever
A photograph of the Doomsday Clock, stating "It is 85 seconds to midnight."

Hurricane Erin: See spaghetti models and track the storm’s path online
A map showing the predicted path of Tropical Storm Erin.

Tropical Storm Erin: Spaghetti models track the storm’s path
A prediction cone for Tropical Storm Erin.

NASA to build a nuclear reactor on the moon by 2030, report states
The lunar surface.

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!