The revelation that the data of some 57 million Uber customers and drivers has been leaked, with the company then paying the hackers $100,000 to delete the data and keep quiet about it, has come as yet another ‘nail in the coffin’ to the data security strategies employed by business – both large and small.
Not only did Uber’s systems allow such a hack, they failed to disclose the breach.
Well, here we go again! This seems to be some kind of ransom attack and of course, under the forthcoming GDPR regulations (due to take effect in 2018) such a breach would cost the company dear, some 4% of their global turnover. US regulations do require companies to disclose all breaches and Uber are in clear contravention of this.
It demonstrates the weakness of cloud based technology when it comes to adequately securing data in storage. Whilst it seems that this data was not encrypted – an unbelievable situation in today’s climate – non-the-less, even if it had been, it may not have prevented the breach, should the hackers have had access to the right credentials.
To read the full article in Business Computing World, click here