Kiwis hit by Uber hack, no sign yet the data's been used
Thursday, 23 November 2017
New Zealand information was stolen in the cyberattack on Uber that compromised data from 57 million riders and drivers.
Uber spokeswoman Nicky Preston confirmed the hack had reached New Zealand Uber users.
Preston said 'no critical info was downloaded' or had been released, like drivers' licences or credit cards. However, the names, phone numbers and email addresses of New Zealand users had been accessed by the hackers.
'We're not releasing numbers and to be completely honest I don't know the scale.
READ MORE:
* **Uber admits concealing cyberattack that exposed 57 million people's personal data
* Uber faces multiple European probes into hidden hacking attack**
'While we have not seen evidence of fraud or misuse tied to the incident, we are monitoring the affected accounts and have flagged them for additional fraud protection,' she said.
Fifty million riders had their addresses, phone numbers, names and emails compromised, and seven million drivers were accessed as well, including 600,000 United States driver's license numbers.
Uber informed the Privacy Commissioner of the incident on Wednesday, although the hack took place in October 2016, the company told Bloomberg.
The company paid hackers US$100,000 (NZ$145,000) to delete the data and keep the breach quiet.
Then chief executive Travis Kalanick was reportedly told about the breach a month after it occurred.
Privacy Commissioner John Edwards said: 'We are disappointed that although this breach occurred in October 2016, we are only now hearing the details.
'This kind of incident underscores the importance and urgency of mandatory breach reporting laws, which the Government has been considering since 2011.'
In a report tabled in Parliament in February, Edwards recommended giving the commission the power to impose civil penalties for serious breaches of privacy under the Privacy Act.
At present, criminal fines for privacy breaches are $2000 for an individual and $10,000 for a corporation, and the bulk of enforcement happens through the Human Rights Review Tribunal.
Edwards also recommended raising damages to $100,000 for an individual and up to $1 million for a corporation.
Italian, Dutch, and British privacy watchdog agencies have announced a probe into the hack, despite having minimal or no power to issue fines and penalties.
The Privacy Commission has said it is monitoring the situation and may investigate individual complaints by people whose information was lost in the breach.
Uber's new chief executive, Dara Khosrowshahi, wrote in a blogpost the information was accessed by two individuals through a third-party cloud-based service that Uber uses.
Forensics experts have seen no indication that trip location history, credit card numbers, or bank account details had been accessed, Uber said.
Uber said the hackers were subsequently identified, and the company 'obtained assurances that the downloaded data had been destroyed'.