Uber faces investigations by 5 US state AGs and at least 3 potential class actions, and has been contacted by FTC over recently disclosed hack and $100K ransom
After Uber revealed that it paid hackers $100,000 to keep quiet about stealing the personal information of 57 million customers and drivers …
Context & Ripple Effects
The disclosure that Uber paid hackers $100,000 to delete data on 50M riders and 7M drivers has escalated fast: New York's attorney general opened a cover-up probe days ago, and now five state AGs plus the FTC are involved. The legal stack was already heavy — sources reported in October that Uber faced at least five criminal probes from the US DoJ, including possible price-transparency violations five criminal DoJ probes.
First-order effects
- Uber's CSO is already fired and its legal exposure widens immediately: five state AG investigations, FTC contact over the ransom payment, and at least three potential class actions from affected riders and drivers.
Second-order effects
- The cover-up itself becomes the chargeable conduct — as New York's $100,000 hack cover-up investigation shows, regulators are treating the concealment and non-disclosure as a separate offense from the breach, raising the cost of quiet settlements for any company weighing one.
Third-order effects
- The arc points toward mandatory-breach-disclosure enforcement with teeth: Uber ultimately admitted failing to inform the FTC of the November 2016 hack in a settlement that let it avoid criminal charges admitting failure to inform the FTC, and later agreed to an expanded settlement requiring bug-bounty retention and exposing it to civil penalties for future disclosure failures expanded FTC settlement.
The trend: Data-breach concealment is becoming costlier than the breach itself, as state AGs, the FTC, and class-action plaintiffs converge on companies that pay to suppress disclosure.