← All enforcement actions
State Breach NotificationMobility

Uber$148M CCPA fine (2018)

Paid hackers $100K to hide a 57M-record breach for over a year

Penalty
$148M
Regulator
50 State AGs + DC
Jurisdiction
United States
Records affected
57M

What happened

Attackers stole 57M rider + driver records via credentials posted to a private GitHub repo. Uber paid the attackers $100K through its bug-bounty program in exchange for silence and did not notify regulators for over a year. A 50-state settlement totaled $148M; the security chief was later criminally convicted.

Root cause

What every team should do

  1. Enable secret-scanning + push-protection on every repo (GitHub, GitLab, Bitbucket)
  2. Short-lived credentials only — never long-term IAM access keys
  3. Pre-author + practice the breach-notification decision tree; do not rebrand incidents
  4. Make legal + compliance review of any bug-bounty payout above a threshold
Source: State AG settlement (Sep 26, 2018).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which CCPA controls you are missing — mapped to enforcement patterns like this one.

Run my CCPA audit Generate missing policies

Related enforcement actions

Didi Global
¥8.026B (~$1.2B)
Largest data-protection fine in Asia — 16 violations across PIPL, DSL, CSL