{"database": "press", "table": "releases", "rows": [["https://www.warner.senate.gov/public/index.cfm/2017/11/sen-warner-questions-uber-ceo-on-handling-of-data-breach-presses-company-on-decision-to-conceal-breach-from-drivers-consumers", "Sen. Warner Questions Uber CEO On Handling of Data Breach, Presses Company on Decision to Conceal Breach from Drivers, Consumers", "2017-11-27", "2017", "2017-11", "Democrat", "House", "VA", "Mark Warner", "W000805", "www.warner.senate.gov", null, null, "legacy", "WASHINGTON \u2013 U.S. Sen. Mark R. Warner (D-VA), Ranking Member of the Senate Banking Subcommittee on Securities, Insurance and Investment, today pressed Uber CEO Dara Khosrowshahi on the company\u2019s recent disclosure that hackers accessed the personal information of 57 million users last year. \u00a0Uber paid the hackers $100,000 to pledge to destroy the data \u2013 which included the names and driver\u2019s license numbers of 600,000 drivers, and names, phone numbers, and email addresses of millions of riders \u2013 and did not disclose the hack to regulators or users until last week.\r\nWarner posed the following questions to Khosrowshahi:\u00a0\r\n\r\n \r\nAccording to reports, Uber\u2019s systems were breached after the attackers discovered log-in credentials to an AWS account used to handle payments. Why weren\u2019t more robust access management mechanisms, including strong multi-factor authentication, enabled to prevent unauthorized access to passenger and driver data?\r\nWho conducted the initial investigation for Uber that successfully identified the hackers? What \u201cassurances\u201d were provided by the hackers to prove they did, in fact, delete the compromised data?\u00a0\r\nUnlike ransomware payments, in which payment is made to recover or regain access to inaccessible data or systems, it appears the motivation behind this payment was principally to prevent the public or authorities from learning of the breach. What rationale was provided by senior executives for covering up this breach?\r\nUber has alleged that it was required to provide information relating to the breach and subsequent cover-up to prospective investors. Can you explain why Uber chose not to disclose the breach to drivers and users prior to, or at least at the same time as, a prospective investor?\r\nReports indicate that Uber successfully \u201ctracked down the hackers and pushed them to sign nondisclosure agreements.\u201d While some information necessary to accomplish this could certainly have been gleaned from traditional digital forensic tools, these reports \u2013 combined with Uber\u2019s past pattern of conduct \u2013 raise serious questions about how Uber was able to track down the criminals who breached Uber\u2019s systems and blackmailed the company, and whether these actions might have constituted violations of the Computer Fraud and Abuse Act. As you know, no private right exists for companies to \u201chack back\u201d those who compromise their systems. In the process of tracking down these hackers, did Uber or any authorized party acting on its behalf engage in unauthorized access of third party systems?\r\nUber\u2019s decision to identify the responsible parties and commit them to a non-disclosure agreement thwarts law enforcement\u2019s ability to bring criminal hackers to justice. To the extent Uber had lawfully acquired information enabling it to identify the hackers who had compromised its systems, ensure they would abide by agreements to delete the data and not to disclose the breach, and transfer them $100,000, it conceivably had enough information at hand to assist law enforcement in the apprehension of these criminals. Why did Uber choose not to provide relevant forensic information to law enforcement and has this information been provided to law enforcement in the last week?\r\n \r\n\r\nSen. Warner is a former technology executive and the co-founder of the Senate\u2019s bipartisan Cybersecurity Caucus. Sen. Warner is working to finalize bipartisan legislation to create a comprehensive, nationwide and uniform data breach standard, requiring timelier consumer notification for breaches of financial data and other sensitive information, and setting national data-protection standards for companies handling sensitive personal information.\u00a0\r\nA PDF of the signed letter is available\u00a0here.\r\n\u00a0\r\n\u00a0\r\n###", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.warner.senate.gov/public/index.cfm/2017/11/sen-warner-questions-uber-ceo-on-handling-of-data-breach-presses-company-on-decision-to-conceal-breach-from-drivers-consumers"], "units": {}, "query_ms": 0.6776039954274893, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}