Saturday, January 4, 2025
HomeCyber Security NewsUber Driver Data Stolen Again From the Servers of Law Firm

Uber Driver Data Stolen Again From the Servers of Law Firm

Published on

SIEM as a Service

Uber faces various cyber attacks that result in the disclosure of employee email addresses, company reports, and information related to IT assets.

The servers of Genova Burns, a legal services firm, have been compromised, resulting in the theft of driver data belonging to the company.

Breach Notification

Genova Burns LLC informed the impacted drivers that their information, including their name and either Social Security number or Tax Identification number, which they provided to Uber, has been affected.

- Advertisement - SIEM as a Service

On January 31, 2023, the company noticed suspicious activity on their servers and commenced an investigation into the matter.

Forensic and data security experts spearheaded the investigation to determine the extent of the activity.

Upon further examination, it was discovered that the attack had infiltrated the system and extracted data between January 23, 2023 and January 31, 2023.

Genova Burns LLC suspects that the following information provided by the drivers to Uber has been stolen.

“In connection with this legal representation, we received data regarding certain drivers on the Uber platform, which included information about you.”

As a result of the investigation, it was found that the impacted file contains the following information.

  • Name
  • Social Security number
  • Tax Identification Number

“Upon learning of the event, we investigated to determine the nature and scope of the incident and secured the environment by changing all system passwords.”

Software supply chain attacks won’t stop anytime soon, but software vendors can reduce the risk of supply chain attacks with effective security procedures and awareness training.

The world is advancing, and digitalization is taking over. Therefore, software production and management increase daily. Likewise, attackers implement sophisticated tools to infiltrate and inject malicious codes into vulnerable software.

Searching to secure your APIs? – Try Free API Penetration Testing

Related Read:

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware

LegionLoader, a C/C++ downloader malware, first seen in 2019, delivers payloads like malicious Chrome...

ASUS Critical Vulnerabilities Let Attackers Execute Arbitrary Commands

In a recent security advisory, ASUS has alerted users to critical vulnerabilities affecting several...

NTT Docomo Hit by DDoS Attack, Services Disrupted for 11 Hours

NTT Docomo, one of Japan’s leading telecommunications and IT service providers, experienced a massive...

Apple Agrees to $95M Settlement Over Siri Privacy Lawsuit

Apple Inc. has agreed to pay $95 million to settle a proposed class-action lawsuit...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

LegionLoader Abusing Chrome Extensions To Deliver Infostealer Malware

LegionLoader, a C/C++ downloader malware, first seen in 2019, delivers payloads like malicious Chrome...

ASUS Critical Vulnerabilities Let Attackers Execute Arbitrary Commands

In a recent security advisory, ASUS has alerted users to critical vulnerabilities affecting several...

NTT Docomo Hit by DDoS Attack, Services Disrupted for 11 Hours

NTT Docomo, one of Japan’s leading telecommunications and IT service providers, experienced a massive...