Skip to main content
WhatTermsWhatTerms
← Back to Uber

Breach exposure

Public breaches involving Uber

Cross-matched against the WhatTerms breach catalog. Each entry links the breach disclosure, names the data classes confirmed exposed, and matches each class to a concrete recovery action — not just “your email was leaked”.

Recovery actions

Sorted by severity. Each action maps to one or more data classes confirmed exposed across the breaches below.

  • Treat SMS 2FA on this number as compromised. Move to TOTP or hardware keys; consider a relay number.

    High

    Phone numbers feed SIM-swap attacks and SMS phishing.

  • Audit which other services hold your location and tighten location permissions; revoke historical exports.

    High

    Location traces are uniquely identifying and lifestyle-revealing.

  • Switch this service to a per-service email alias and treat the leaked address as compromised.

    Medium

    Exposed emails feed phishing campaigns and credential-stuffing lists.

  • Audit accounts where you reuse this handle; assume it can be cross-correlated.

    Medium

    Handle reuse links pseudonymous accounts back to your real identity.

  • Watch for targeted phishing referencing your real purchases; treat any unsolicited 'order issue' email as suspect.

    Medium

    Purchase history is the strongest pretext for receipt-based phishing.

Uber

Disclosed 2022-09-15 · 57.0M accounts

Internal systems compromise; customer trip and contact data exposed.

Data classes exposed

  • Email address
  • Username / handle
  • Phone number
  • Geolocation history
  • Purchase history

Source: Uber security advisory; SEC 8-K. Read disclosure ↗