Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Uber

Uber Vendor Cyber Rating & Cyber Score

uber.com

We are Uber. The go-getters. The kind of people who are relentless about our mission to help people go anywhere and get anything and earn their way. Movement is what we power. It’s our lifeblood. It runs through our veins. It’s what gets us out of bed each morning. It pushes us to constantly reimagine how we can move better. For you. For all the places you want to go. For all the things you want to get. For all the ways you want to earn. Across the entire world. In real time. At the incredible speed of now. The idea for Uber was born on a snowy night in Paris in 2008, and ever since then our DNA of reimagination and reinvention carries on. We’ve grown into a global platform powering flexible earnings and the movement of people and things


Uber A.I CyberSecurity Scoring

Uber
Company Information
Website:http://www.uber.com
Employees number:149,805
Number of followers:3,422,223
NAICS:425
Industry Type:Internet Marketplace Platforms
Homepage:uber.com
Uber Risk Score (AI oriented)
Between 750 and 799
logo
UberInternet Marketplace Platforms
Updated:
01/04/2026
759/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Uber Global Score (TPRM)
xxxx
logo
UberInternet Marketplace Platforms
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Uber
UberFair
Current Score
759Baa (FAIR)
01000
10 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
764Before Incident
JULY 2026
763Before Incident
JUNE 2026
762Before Incident
MAY 2026
760Before Incident
APRIL 2026
759Before Incident
MARCH 2026
757Before Incident
FEBRUARY 2026
757Before Incident
JANUARY 2026
756Before Incident
DECEMBER 2025
748Before Incident
NOVEMBER 2025
748Before Incident
OCTOBER 2025
746Before Incident
SEPTEMBER 2025
744Before Incident
APRIL 2023
708Before Incident
Breach
01 Apr 2023Uber
Uber

Uber Data Breach by UberLeaks

677After Incident
CRITICAL-31
UBE23210723
A threat actor named ‘UberLeaks’ recently leaked data that was stolen from Uber and app's drivers on a hacking forum known for publishing data breaches. The leaked data included name and Social Security number and/or Tax Identification number. The leaked data is related to a security breach on a third-party vendor.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data Theft
IMPACT
NameSocial Security numberTax Identification number
DATA BREACH
Personally Identifiable InformationSensitivity Of Data: High
JANUARY 2023
734Before Incident
Breach
23 Jan 2023Uber
Uber Technologies, Inc.

Data Breach at Genova Burns LLC Involving Uber Technologies, Inc.

703After Incident
HIGH-31
UBE328080425
The Maine Office of the Attorney General reported that Genova Burns LLC experienced a data breach involving Uber Technologies, Inc. The breach occurred between January 23, 2023, and January 31, 2023, and impacted the personal data of 10 individuals, including Social Security numbers. The breach was reported on March 31, 2023, and identity theft protection services through Kroll were offered to those affected.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numbersIdentity Theft Risk: High
DATA BREACH
Social Security numbersSensitivity Of Data: HighPersonally Identifiable Information: Yes
DECEMBER 2022
761Before Incident
Breach
01 Dec 2022Uber
Uber

Uber Data Breach by 'UberLeaks'

730After Incident
CRITICAL-31
UBE2233131222
A threat actor named ‘UberLeaks’ recently leaked data that was stolen from Uber and Uber Eats on a hacking forum known for publishing data breaches. The leaked data included numerous archives claiming to be source code associated with mobile device management platforms (MDM) used by Uber and Uber Eats and third-party vendor services. The leaked data is related to a security breach on a third-party vendor.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Source CodeMobile Device Management Platforms (MDM)
DATA BREACH
Type Of Data Compromised: Source Code
SEPTEMBER 2022
768Before Incident
Cyber Attack
01 Sep 2022Uber
Uber

Uber Cyber Attack

757After Incident
CRITICAL-11
UBE1417922
Uber was targeted by a cyber attack, and hackers gained access to security vulnerability information. The alleged hacker compromised an employee's Slack account before taking over Uber's internal systems. The hacker used social engineering instead of complex hacking methods. In order to access company accounts and sensitive data, thieves take advantage of people's credulity and lack of experience in this situation. They are still investigating the incident.
INCIDENT DETAILS -
TYPE
Cyber Attack
MOTIVATION
Unauthorized Access
IMPACT
Security Vulnerability InformationSlackInternal Systems
DATA BREACH
Security Vulnerability Information
DECEMBER 2017
687Before Incident
Breach
01 Dec 2017Uber
Uber

Cybercriminal Hacks Multiple Businesses to Sell Customer Data on the Dark Web

647After Incident
HIGH-40
UBE74122323
A cybercriminal has admitted to hacking businesses like Uber, Sainsbury's, and Groupon to sell customers' personal information on the dark web. The other targets included Nectar, T-Mobile, Asda, Ladbrokes, Coral, and Argos. The data comprised all the information required to complete an online purchase and was then promoted and sold to clients through his dark website. The firm is thought to have lost more than £200,000 due to the theft, although no financial data was collected. West pleaded guilty to two counts of conspiring to defraud, one count of hacking a computer, four counts of possessing and supplying marijuana, two counts of having criminal property, and one crime of money laundering Bitcoins. The leaked data is related to a security breach on a third-party vendor.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Financial Loss: £200,000Data Compromised: Personal information required to complete an online purchase
DATA BREACH
Type Of Data Compromised: Personal information required to complete an online purchaseData Exfiltration: YesPersonally Identifiable Information: Yes
NOVEMBER 2017
728Before Incident
Breach
01 Nov 2017Uber
Uber

Uber Data Breach

684After Incident
CRITICAL-44
UBE229181223
Uber CEO Dara Khosrowshahi revealed that hackers had gained access to the personal information of 57 million of the firm's users by breaking into the company database. About 600,000 drivers in the US have had their identities and driver's licence numbers compromised by the attackers. In an attempt to coerce Uber, the hackers sought $100,000 in return for not disclosing the stolen information. The CEO clarified that because Uber built its company on the security and confidence of its clients, incidents of this nature won't occur again.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Personal InformationDriver's Licence NumbersBrand Reputation Impact: NegativeIdentity Theft Risk: High
DATA BREACH
Personal InformationDriver's Licence NumbersSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
FEBRUARY 2017
740Before Incident
Data Leak
01 Feb 2017Uber
Uber

Cloudbleed Security Flaw

709After Incident
CRITICAL-31
UBE634191123
Cloudflare was disclosing a lot of private data, including login passwords and authentication cookies. Uber, Fitbit, 1Password, and OKCupid are just a few of the big names affected by the Cloudbleed security flaw in Cloudflare servers. Because mobile apps are created with the same backends as browsers for HTTPS (SSL/TLS) termination and content delivery, they are likewise impacted by Cloudbleed. The fact that Cloudflare directed Ormandy to the company's bug bounty programme and offered the expert a t-shirt as payment in lieu of cash is highly unusual.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
login passwordsauthentication cookies
DATA BREACH
login passwordsauthentication cookies
OCTOBER 2016
768Before Incident
Breach
13 Oct 2016Uber
Uber Technologies, Inc.

Uber Data Breach

734After Incident
HIGH-34
UBE1009072525
The Washington State Office of the Attorney General reported a data breach involving Uber Technologies, Inc. on November 21, 2017. The breach occurred between October 13, 2016, and November 15, 2016, affecting the names and driver's license numbers of approximately 10,888 drivers in Washington State. Uber took remedial actions including providing credit monitoring services for the affected individuals.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesDriver's License Numbers
DATA BREACH
NamesDriver's License NumbersSensitivity Of Data: High
JUNE 2016
808Before Incident
Breach
16 Jun 2016Uber
Uber

Uber 2016 Data Breach Concealment and Legal Conviction of Former Security Chief Joseph Sullivan

764After Incident
CRITICAL-44
UBE4092840111225
In 2016, Uber suffered a major data breach in which hackers accessed a third-party cloud service and stole personal data of 57 million users (drivers and riders), including names, email addresses, and phone numbers, as well as driver’s license numbers for 600,000 drivers. Instead of disclosing the incident to regulators (the US Federal Trade Commission) and affected individuals, Uber’s then-Chief Security Officer, Joseph Sullivan, orchestrated a cover-up. The company paid the hackers $100,000 in ransom (disguised as a bug bounty) to delete the data and keep the breach secret. The concealment lasted over a year, violating breach notification laws and leading to Sullivan’s 2023 conviction for obstruction of justice and mispriison of a felony (failure to report a crime). The breach exposed Uber to regulatory fines, reputational damage, and legal liabilities, while eroding trust among users and drivers. The case underscored the risks of non-compliance with data protection laws and the severe consequences of executive-level misconduct in cybersecurity incidents.
INCIDENT DETAILS -
TYPE
Data BreachRegulatory ViolationLegal Conviction
MOTIVATION
Financial Gain (extortion)Cover-up of Security Failures
IMPACT
Personal data of 57 million Uber users and drivers (names, email addresses, phone numbers)Driver’s license numbers for ~600,000 US driversUber’s AWS data storageGitHub repositoriesOperational Impact: Internal investigation and leadership changes, including termination of Sullivan and other executivesCustomer Complaints: Increased distrust and public backlash following delayed disclosureBrand Reputation Impact: Severe damage due to concealment of breach and misleading public statements; long-term erosion of trustFTC settlement (2018) for $148 millionCriminal conviction of Joseph Sullivan (2023) for obstruction and misprisionPotential class-action lawsuitsIdentity Theft Risk: High (due to exposure of PII and driver’s license numbers)Payment Information Risk: None reported
DATA BREACH
Personally Identifiable Information (PII)Driver’s license numbersNumber Of Records Exposed: 57 million (50 million riders, 7 million drivers)Sensitivity Of Data: High (includes government-issued IDs)Data Exfiltration: Yes (data downloaded by attackers)Data Encryption: No (data stored unencrypted in AWS)DatabasesLog filesPersonally Identifiable Information: Yes (names, emails, phone numbers, driver’s license numbers)
MAY 2014
828Before Incident
Breach
13 May 2014Uber
Uber Technologies, Inc.

Uber Data Breach

796After Incident
HIGH-32
UBE401072925
The Washington Attorney General's Office reported a data breach involving Uber Technologies, Inc. on June 16, 2016. The breach, which occurred on May 13, 2014, involved unauthorized access to a database affecting 1,355 Washington residents, compromising their names and driver's license numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesDriver's License Numbers
DATA BREACH
NamesDriver's License NumbersSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Uber ?
?
What was Uber's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Uber's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Uber's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Uber's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Uber's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Uber's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Uber's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Uber's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Uber's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Uber's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Uber's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Uber's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Uber ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Uber's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?