Two grey hat hackers have pleaded guilty to committing extortion attacks on Uber, LinkedIn and other US companies .
Specifically, the two hackers admitted that they demanded large sums of money from the companies and promised that if they gave them the money, they would not use the data of millions of customers, which they had stolen in late 2016.
On Wednesday, during their trial in California, the two defendants, Brandon Charles Glover (26) of Florida and Vasile Mereacre (23) of Toronto, admitted to using stolen credentials to gain access to the systems . They then stole various data.
Once they had the data at their disposal, they contacted the companies to report the existence of vulnerabilities and demanded money.
"I was able to access backups .Me and my team want a huge reward for this," the hackers said in an email sent to one of the victims.
"Please note that we expect a large payout, as this was hard work for us.".
According to a report by The Hacker News, two years ago, hackers managed to obtain sensitive information from 57 million Uber driver-customers. The company gave the two hackers $100,000 in bitcoinin an attempt to cover up the breach.
“The defendants used false names to contact the victim companies and, in several cases, informed the victims that other companies were paying them to find vulnerabilities,” the indictment states.

They also sent the victims some samples of the data, to convince them that the hackers were indeed in possession of the company's data.
Additionally, according to the charges, the two hackers blackmailed LinkedIn in the same manner in December 2016. They informed the company that they had breached the databases of its subsidiary Lynda.com and that they had stolen over 90,000 records (and credit card information).
At the time, news broke that Uber had sent a team of experts to the hackers' homes to search computers and make sure all the stolen data was no longer available to them. In fact, they are said to have signed a non-disclosure agreement about the breach.
Uber disclosed the incident a year later. The company was forced to pay $148 million to conduct an investigation, while British and Dutch data protection regulators imposed a fine of $1.1 million for failing to protect customers' personal information.
Uber did not disclose the incident to the US Federal Trade Commission (FTC), which was investigating another incident involving the company at the time. The commission was also informed a year later.
The two defendants, Glover and Mereacre, who pleaded guilty to conspiracy to commit racketeering, are awaiting sentencing in March 2020. Their sentence is expected to be up to five years in prison and a $250,000 fine.
