Uber has revealed that the personal data of some of its drivers may have been stolen in a third-party breach. The ride-hailing company stated that an outside legal counsel, Genova Burns LLC, suffered a security incident in March, which may have stolen certain drivers’ information, including social security numbers and/or tax identification numbers.
Impacted drivers who completed trips in New Jersey have been notified that their social security number and/or tax identification number may have been potentially compromised. Uber has offered these drivers complimentary credit monitoring and identity protection services to help mitigate the risk of identity theft or other fraudulent activity.
Genova Burns has stated that they are not aware of any actual or attempted misuse of the information and has confirmed that they are taking additional steps to improve security and better protect against similar incidents in the future.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The incident is a reminder of the importance of cybersecurity and the risks of third-party breaches. While Uber has stated that the security incident did not directly impact it, the potential theft of drivers’ personal information underscores the need for robust cybersecurity measures and regular monitoring of third-party providers’ security protocols.
To protect yourself, it is essential to take proactive steps to safeguard your personal information. This includes regularly changing passwords, enabling two-factor authentication, and monitoring bank and credit card statements for suspicious activity. Limiting the amount of personal information you share online and being cautious of suspicious emails or messages that ask for sensitive data is also advisable.
In light of this incident, all companies must review and strengthen their cybersecurity protocols, particularly those that handle personal data. While Uber has taken steps to address the breach, it is important for affected drivers and all individuals to remain vigilant and proactively protect their personal information.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Citrix NetScaler CVE-2026-19490: The Auth Bypass That Went From PoC to Probes in a Day
CVE-2026-19490 is a CVSS 9.3 NetScaler Gateway/AAA auth bypass. A public PoC on Sept 2 was followed by live probes within a...
PaperCut NG/MF: The Print Server That Learned Remote Code Execution Again
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Confirm Emergency Patch Release 2, restrict admin exposure, and hunt like...
JFrog Artifactory CVE-2026-82329: Empty Join Key, Full Admin Token, Busy Scanners
CVE-2026-82329 lets attackers forge Artifactory admin tokens via a deterministic empty join key. Mass scanning peaked near 406,000 attempts; patch fixed builds...
The 5-Minute Cyber Brief: September 14, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.