Uber has reached a settlement with every state in the United States over a data breach it suffered in 2016 that it never disclosed. The company will now pay a total of $148 million (the amount varies by state), a lawyer said. It will also be required to adopt additional security measures and practices that it has not yet implemented.

“Uber’s decision to keep this breach a secret is a breach of trust between the company and its public. The company failed to safeguard its data, and to inform authorities of what happened.” Uber intentionally tried to hide the breach it suffered, violating the county.
In 2016, unknown hackers managed to breach the company's systems, and extract personal information from 57 million Uber drivers and customers. The data that was extracted contained personal information, such as names, emails, and copies of drivers' licenses. Fortunately, it did not contain credit card information. At the time of the breach, Uber paid the hackers $100,000 to delete the stolen data.
It was initially unclear how the hacker was paid, but it was later revealed that a 20-year-old man from Florida was behind the attack. The payment was reportedly made through a bug bounty program.
"None of this should have happened, but I will not make excuses for this. While I cannot change the past, I can guarantee that we have now learned from our mistakes," said Dara Khosrowshahi, CEO of Uber.
