
The Uber taxi order service concluded a judicial agreement as part of a collective claim of the 50 states of the United States and the Federal District of Colombia, which was filed against the company due to its concealment of 57 million customers and 600 thousand drivers.
"As part of the national settlement, Uber agreed to pay $ 148 million. Iowa will receive $ 612.9 thousand, which will be sent to the consumer education and court proceedings," the Ayova Prosecutor General Tom Miller said.
In addition to cash payments, Uber has given the obligation to notify users of a possible leakage of their data. In addition, the company should take precautions to protect user information that Uber stored in third parties, writes RBC .
The terms of the agreement also oblige Uber to form a data security policy. This policy should take into account potential risks and provide protective measures in case of cyber attacks. Finally, Uber will have to find external experts who will conduct regular checks for data security.
Recall that Uber leakage occurred in October 2016, but the company reported it only at the end of November 2017. Then the Uber specified that they paid for the destruction of the stolen files 100 thousand dollars, but the details about hackers and how the transfer of money was organized were not disclosed. At the same time, the head of Uber, Dara Khosrovshahi, said that the company fired the head of the Security Service of Joe Sullivan and lawyer Craig Clack in connection with the leak.
In December 2017, it became known that a 20-year-old young man from Florida received a ransom of 100 thousand dollars. The hacker was transferred to the hacker as part of the Bug Bounty program, which provides for encouragement for cybersecurity specialists for information about the vulnerabilities found. Who exactly in the company's management ordered the hacker to pay the ransom and keep the fact of leakage secret was not specified, although the sources claimed that the founder and former head of Uber Travis Kalanik knew about this situation. It was also reported that after transferring the money, the company was convinced that the stolen data was deleted and forced the hacker to sign an agreement on non -disclosure.