Uber Drivers’ Data Exposed in Breach of Law Firm’s Servers

A mid-sized law firm representing Uber has notified an unknown number of drivers that sensitive data has been exposed and stolen in a cyberattack. New Jersey-based Genova Burns disclosed the breach in an email to customers it first obtained. register.

“We have determined that between January 23, 2023 and January 31, 2023, an unauthorized third party accessed our systems and accessed or stole certain limited files.”

“During our investigation, we have determined that the affected data includes information you provided to Uber, including your name, social security number, and tax identification number.”

Read more about Uber’s data breach: Uber suffers new data breach after attack on third-party vendor

Jenova Burns added that she is currently investigating the incident with law enforcement. The company said it has changed her password on all systems and is offering the affected driver a 12-month free ID monitoring service through Kroll.

According to Krishna Vishnubhotra, Vice President of Product Strategy at Zimperium, more and more businesses are relying heavily on third-party services.

“A typical enterprise business uses over 1000 cloud services and applications, many of which are third-party services.”

However, Vishnubhotla added that the central issue of the practice is the exchange and monetization of sensitive data between various parties.

“When this happens, it’s difficult for any company to keep track of where this data is and whether it’s properly protected.”

As a result, Pathlock CEO Piyush Pandey advised, “Third-party access to core business systems should be governed by the strictest access controls.”

Executives said that for a public and regulated company like Uber, third-party access comes with specific regulations to ensure controls are enforced in a highly monitored manner. explained that there are many

“A common challenge organizations face with third-party access management is the lengthy review process,” added Pandey.

“To be truly effective, organizations need to be more proactive about automating workflows around third-party access reviews and adjusting policies to mitigate risk wherever possible.”

More information on how businesses can defend against similar data breaches is available in this analysis by Rich Turner, Senior Vice President of EMEA at CyberArk.

Editorial image credit: Ink Drop / Shutterstock.com

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *