Washington state sues Uber for failing to promptly notify ~10K users that their data was accessed in recent breach, seeks up to $2K per violation
Monica Nickelsburg / GeekWire :
Context & Ripple Effects
Uber's disclosure of a year-old hack involving a $100K ransom put it in front of five state attorneys general and at least three potential class actions [[a:924367]]; Washington's suit is the first of those AGs converting scrutiny into a filed claim, seeking up to $2,000 per violation for roughly 10,000 users whose data was accessed without prompt notice.
The playbook spread quickly: Pennsylvania followed with its own suit over Uber waiting more than a year to disclose the same breach to about 13,500 drivers [[a:927274]], and the multi-state pressure eventually produced a $148M settlement covering all 50 states [[a:933923]]. Washington's per-violation theory is what made the aggregate number so large.
First-order effects
- Uber now faces statutory damages of up to $2,000 per affected user on top of the federal FTC contact and class-action exposure it was already carrying when the breach surfaced.
- The roughly 10,000 Washington users gain a state-backed enforcement path to compensation that individual claims could never have funded.
Second-order effects
- Other state AGs watching the case have a template for stacking per-violation penalties on top of notification-failure claims, which is exactly how Pennsylvania's parallel suit and the eventual 50-state settlement took shape.
- Consumer platforms holding driver and rider data face rising expected costs of sitting on a breach, shifting the calculus toward immediate disclosure even at reputational expense.
Third-order effects
- If the pattern holds, breach-concealment becomes a coordinated multi-state enforcement product rather than a patchwork of isolated suits — the structure that turned one hidden 2016 hack into a nine-figure, nationwide settlement.
- State AG offices emerge as the de facto enforcers of data-security duty for national platforms, a role Washington extended years later by suing T-Mobile over its handling of a cyberattack affecting 2M+ residents [[a:881126]].
The trend: State attorneys general are turning delayed breach disclosure into a repeatable, per-violation enforcement model that prices concealment out of the market for consumer-data platforms.