Uber sends hacking victim new password in plain text email
Hacked Uber user highlights taxi firm's security response issues


Uber's security policy has come under scrutiny after another user had her account hacked.
The taxi app company reportedly took more than 24 hours to respond to the New York-based user, who found calls and charges from the UK had appeared on their account, according to Motherboard.
Hackers have targeted Uber accounts before, but the latest incident not only resulted in a delay, but with Uber sending the victim her new password in a plain text email.
When Uber eventually responded to complaints about the incident, it was with an email informing the user that they had changed their password, writing it in a plaintext email.
This is a well-known security misstep, lacking the basic encryption preventing hackers from finding the password in such an email.
George Rosamond, a system administrator specialising in privacy and security, told Motherboard: "These companies act like innovators, but in reality they really are reusing old infrastructures and practices. A little time and energy spent approaching the old security questions could go a long way."
Whether this was the fault of one Uber employee or something indicative of Uber's general security policies is currently unclear, but the experience did lead the user in question to request Uber delete their account and all information associated with it.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The news comes a week after Uber reportedly put together a $3 billion bid for Nokia's mapping service, known as Here.
Uber currently relies on Google Maps, but wants to own its own technology as Google works on developing driverless cars.
While Google Maps is by far the most popular mapping tool, Nokia's Here dominates the automobile space.
Caroline has been writing about technology for more than a decade, switching between consumer smart home news and reviews and in-depth B2B industry coverage. In addition to her work for IT Pro and Cloud Pro, she has contributed to a number of titles including Expert Reviews, TechRadar, The Week and many more. She is currently the smart home editor across Future Publishing's homes titles.
You can get in touch with Caroline via email at caroline.preece@futurenet.com.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Uber hit with €290m fine for storing European driver data in the US
News The fine marks the latest imposed on Uber by the Dutch data protection authority
By Emma Woollacott
-
Uber says compromised third-party to blame for data breach
News Vulnerable third-party vendor Teqtivity sparks second major incident for Uber in the space of three months
By Ross Kelly
-
Uber launches infosec hiring spree after attributing breach to LAPSUS$
News The company also hinted at the belief that LAPSUS$ was also behind the attack on Rockstar Games over the weekend in a revealing update detailing the inner workings of the attack
By Connor Jones
-
Uber hacked via basic smishing attack
News The self-taught hacker impersonated an IT worker to gain an Uber employee's password, obtaining broad access to internal systems and posting taunting messages
By Rory Bathgate
-
Former Uber security chief to face fraud charges over hack coverup
News This is thought to be the first instance of a corporate information security officer criminally charged with concealing a hack
By Zach Marzouk
-
Former Uber CSO charged for data breach cover-up
News Joseph Sullivan allegedly paid $100,000 to conceal the ride-hailing firm's 2016 data breach
By Bobby Hellard
-
Uber CISO: There was no justification for hiding data breach
News Senators slam taxi firm for cover-up of hack affecting 57 million people
By Adam Shepherd
-
ICO: Uber data breach raises huge concerns
News The ICO and NCSC will investigate the impact on UK customers
By Clare Hopping