Uber $148 Million Data Breach Settlement: Where the Money Actually Went
Last updated: August 3, 2026
Uber has another settlement — see all Uber settlements.
The $148 million Uber settlement was not a class action and never paid riders. It was an agreement announced on September 26, 2018 between Uber Technologies, Inc. and the attorneys general of all 50 states and the District of Columbia, resolving their investigations into Uber's decision to conceal a November 2016 data breach for a full year. The money was divided among the states, not distributed to the 57 million people whose data was taken.
One state turned its share into direct payments. Texas received more than $6.4 million and said most of it would be returned to Uber drivers in the state, providing eligible Texas drivers with a $100 payment each. Eligibility was narrow and specific: drivers whose driver's license numbers were accessed in the 2016 breach, including people who had already stopped driving for Uber. New York received about $5.1 million with no equivalent driver payment announced.
There is no consumer class action money either, and the reason is arbitration. About 14 lawsuits were consolidated as In re Uber Technologies, Inc., Data Security Breach Litigation, MDL No. 2:18-ml-02826, in the U.S. District Court for the Central District of California. On September 5, 2018 the court held that the claims had to go to individual arbitration, because riders and drivers had agreed to an arbitration clause when they signed up. The MDL was terminated on September 30, 2022 without a class settlement or a class fund.
The Federal Trade Commission's separate action produced no money at all for consumers. Its expanded order, finalised in October 2018 (FTC Docket No. C-4662, File No. 152-3054), required Uber to maintain a comprehensive privacy program with biennial independent assessments for 20 years and exposed it to civil penalties for failing to report future incidents — obligations, not payments. Uber's former chief security officer was separately convicted of two felonies over the cover-up.
Key facts
- Total settlement
- $148 million
- Who received it
- All 50 state attorneys general and Washington, DC
- Consumer fund
- None — no rider or nationwide driver fund
- Texas share
- More than $6.4 million, most returned to drivers
- Texas driver payment
- $100 each, for drivers whose license numbers were accessed
- New York share
- About $5.1 million
- Announced
- September 26, 2018
- Breach date
- November 2016; disclosed November 2017
- People affected
- 57 million worldwide — 25 million US riders, 7.7 million US drivers
- Driver's licences exposed
- About 600,000 US drivers
- Paid to the hackers
- $100,000, to conceal the breach
- Class action outcome
- Sent to individual arbitration September 5, 2018; MDL closed September 30, 2022
- FTC order
- Docket C-4662, File No. 152-3054 — no consumer money; 20 years of assessments
- Criminal case
- Former CSO Joseph Sullivan convicted of two felonies (October 2022); 3 years' probation and a $50,000 fine
Official settlement administrator: New York Attorney General — $148 million Uber settlement announcement
Who qualifies
- There was never a nationwide claim form for the 2016 Uber breach. The $148 million went to state governments, so for most people there was nothing to apply for.
- The one direct-payment route was in Texas: eligible Uber drivers there received a $100 payment funded from the state's share of more than $6.4 million.
- Texas eligibility was limited to drivers whose driver's license numbers were accessed during the 2016 breach — roughly 600,000 US drivers had licence data taken nationwide. Drivers who had since stopped driving for Uber remained eligible.
- Riders were not eligible for a payment anywhere. Rider data taken in the breach was names, email addresses and mobile phone numbers, and no state announced rider payments.
- Everyone else's claims went to individual arbitration rather than a class action, following the Central District of California's September 5, 2018 ruling enforcing Uber's arbitration clause. Individual arbitration remains theoretically available under the terms you agreed to, but there is no fund, no administrator and no deadline-driven claim process attached to it.
The breach Uber hid, and why almost nobody was paid
- 1
November 2016 — the breach, and the payoff
In November 2016 hackers in the United States and Canada contacted Uber's security team to say they had downloaded personal information belonging to 57 million riders and drivers. Using an access key, the intruders pulled unencrypted files from Uber's cloud storage containing more than 25 million names and email addresses, 22 million names and mobile phone numbers, and 600,000 names paired with driver's license numbers. Uber paid the hackers $100,000 and obtained assurances that they had deleted the data.
- 2
The concealment — and why it was worse than the breach
Uber did not disclose the incident until November 2017, a full year later. The delay is what made this a record enforcement matter: Uber was already under FTC investigation over its data security practices at the time, and it did not tell the FTC either. Affected drivers were not told that their driver's license information had been taken, which state attorneys general said deprived them of the chance to protect themselves from identity theft and fraud during the year of silence.
- 3
September 5, 2018 — the class actions are sent to arbitration
About 14 lawsuits were consolidated as In re Uber Technologies, Inc., Data Security Breach Litigation, MDL No. 2:18-ml-02826, in the Central District of California. On September 5, 2018 the court granted Uber's motion to compel arbitration: riders and drivers had accepted an arbitration provision in Uber's terms when they registered. The plaintiffs argued the clause did not cover a data breach, that it was unconscionable, and that riders never received reasonable notice of the electronic terms. The court rejected each argument. This single ruling is why there is no Uber breach class action settlement — the claims left the class device entirely.
- 4
September 26, 2018 — the $148 million state settlement
All 50 state attorneys general and the District of Columbia announced a $148 million agreement, the largest multistate data breach settlement at the time. It resolved the states' claims that Uber violated state breach notification laws by concealing the incident. The money was allocated among the states as civil recoveries. Uber also agreed to adopt strong data security policies, use multi-factor authentication, run a corporate integrity reporting program, protect user data held on third-party platforms, and obtain independent third-party security assessments.
- 5
Texas — the one place drivers were actually paid
Texas received more than $6.4 million and Attorney General Ken Paxton said most of it would be returned to Uber drivers across the state, in the form of a $100 payment to each eligible driver. Eligible drivers were those whose driver's license numbers were accessed during the 2016 breach, and the state noted that drivers who had stopped driving for Uber were still eligible. A settlement administrator was appointed to notify and pay them. This is the detail most coverage omits, and it is the only direct consumer-facing payment the $148 million produced.
- 6
October 2018 — the FTC order, which contained no money
The FTC had already been investigating Uber over a 2014 breach when the 2016 incident happened and went unreported. It renegotiated its settlement into an expanded order, given final approval in October 2018 under Docket No. C-4662 (File No. 152-3054). Uber must implement a comprehensive privacy program and, for 20 years, obtain biennial independent third-party assessments and submit them to the Commission; it can face civil penalties if it fails to notify the FTC of future incidents involving unauthorized access to rider or driver information. No consumer refunds were part of it — FTC orders sometimes carry redress and sometimes carry only obligations, and this one is the second kind.
- 7
October 2022 — a criminal conviction for the cover-up
Joseph Sullivan, Uber's former chief security officer, was prosecuted in the Northern District of California and convicted by a federal jury in October 2022 of obstructing an FTC proceeding and misprision of a felony. Prosecutors showed he learned of the hack on November 14, 2016 — ten days after testifying to the FTC about Uber's security — told a subordinate they "can't let this get out," and arranged to pay the hackers under non-disclosure agreements that falsely stated no data had been taken. He was sentenced to three years' probation and a $50,000 fine. Uber itself entered a non-prosecution agreement with the Department of Justice.
- 8
September 30, 2022 — the MDL closes with no class fund
The consolidated federal litigation was terminated on September 30, 2022. No class was certified for settlement, no notice was ever mailed to a class, and no fund was created. If you are searching for an Uber data breach claim form, this is the answer: one was never created, because the case never reached the stage that produces one.
- 9
What to do if your licence data was taken
A driver's license number, unlike a card number, is not reissued easily, and it is used to open accounts and file fraudulent claims. A free security freeze at Equifax, Experian and TransUnion blocks new credit accounts and must be placed at each bureau separately. If your licence was misused, IdentityTheft.gov is the FTC's free service for an official identity theft report and a recovery plan. Neither is a settlement claim — they are the practical remedies that exist where a settlement did not.
Missed this one? Don't miss the next.
ClaimBee matches your profile against 2,000+ active settlements, shows payout and proof requirements up front, and tracks every deadline for you.
Frequently asked questions
Did anyone get money from the Uber $148 million settlement?
State governments did. The $148 million was divided among all 50 state attorneys general and the District of Columbia, not paid into a consumer fund. The one exception that reached individuals was Texas, which received more than $6.4 million and used most of it to pay eligible Uber drivers in the state $100 each. Riders received nothing anywhere in the country, and no other state announced a comparable driver payment.
Can I still file a claim for the Uber data breach?
No, because a claim process was never created. The $148 million state settlement had no consumer claim form, and the consolidated class actions were ordered into individual arbitration on September 5, 2018, so no class fund or administrator ever existed. The federal MDL closed on September 30, 2022 without a class settlement. Individual arbitration under Uber's terms is the only theoretical route, and it has no deadline-driven claim process attached to it.
Who was eligible for the $100 Texas Uber driver payment?
Uber drivers in Texas whose driver's license numbers were accessed during the 2016 breach. The Texas Attorney General's office specifically noted that drivers who were no longer driving for Uber remained eligible, and that a settlement administrator would be appointed to provide notice and payment. About 600,000 US drivers had driver's license data exposed nationwide, but only Texas converted its share of the settlement into per-driver payments.
Why did the Uber breach class action not result in a settlement?
Because it was forced out of court. About 14 lawsuits were consolidated as MDL No. 2:18-ml-02826 in the Central District of California, and on September 5, 2018 the court granted Uber's motion to compel arbitration — riders and drivers had agreed to an arbitration clause when registering. Plaintiffs argued the clause did not apply to a data breach, that it was unconscionable, and that users lacked reasonable notice of the terms; the court rejected all three. Without a class, there was no vehicle to create a settlement fund.
How many people were affected by the 2016 Uber breach?
57 million riders and drivers worldwide, including 25 million US riders and 7.7 million US drivers. The stolen files held more than 25 million names and email addresses, 22 million names and mobile phone numbers, and about 600,000 names with driver's license numbers belonging to US drivers. No trip histories, credit card numbers, bank account numbers or Social Security numbers were reported taken.
Did Uber really pay the hackers to keep the breach quiet?
Yes. Uber paid the hackers $100,000 and obtained assurances that they had deleted the data, then did not disclose the incident until November 2017 — a year later. The payment was structured through non-disclosure agreements that, according to federal prosecutors, falsely represented that the hackers had not taken or stored any data. That concealment, rather than the breach itself, is what drove the record $148 million state settlement and a criminal conviction.
Was anyone punished personally for the Uber cover-up?
Yes. Joseph Sullivan, Uber's former chief security officer, was convicted by a federal jury in the Northern District of California in October 2022 of obstructing a Federal Trade Commission proceeding and misprision of a felony. He was sentenced to three years' probation and ordered to pay a $50,000 fine. Uber itself entered a non-prosecution agreement with the Department of Justice.
Is this the same as the Uber and Lyft Massachusetts settlement?
No. They are unrelated. The Massachusetts settlement was a $175 million agreement with the state attorney general over driver pay and benefits — a labour case that paid drivers directly, with money distributed by an administrator. This $148 million settlement is about Uber concealing a 2016 data breach and was paid to state governments rather than to drivers, except in Texas. If you are waiting on an Uber payment as a driver, the Massachusetts case is the far more likely source.
Sources and official records
Every figure and date on this page was taken from the primary records below — court dockets, agency releases, and the settlement administrator's own notices. Payout averages we describe as averages are calculated from the official totals, not reported per-person estimates.
- New York Attorney General — record $148 million settlement, breach scope, the $100,000 hacker payment, New York's $5.1 million share
- Texas Attorney General — Texas's $6.4 million share and the $100 payment to eligible Texas drivers whose licence numbers were accessed
- FTC — final approval of the expanded Uber order (Docket C-4662): comprehensive privacy program, 20 years of biennial assessments, no consumer redress
- DOJ (N.D. Cal.) — former Uber CSO Joseph Sullivan convicted of obstructing the FTC and misprision of a felony over the cover-up
- DOJ (N.D. Cal.) — Sullivan sentenced to three years' probation and a $50,000 fine
- CourtListener — In re Uber Technologies, Inc., Data Security Breach Litigation, MDL 2:18-ml-02826 (C.D. Cal.), terminated September 30 2022 with no class settlement
Related settlements
Closed · Gig economy
Uber & Lyft $175 Million Massachusetts Driver Settlement
Automatic back pay · Paid automatically (fall 2025)
Closed · Data privacy
Google Location Tracking Settlement
None — $0 to individuals · No claim available
Closed · Data breach
Morgan Stanley $60 Million Data Breach Settlement
Fraud insurance + up to $10,000 · Closed in 2022
Closed · Data breach
Experian / T-Mobile Data Breach Settlement
Documented losses up to $10,000 · time at $20/hour · Closed April 11, 2019
Closed · Data breach
T-Mobile $350 Million Data Breach Settlement
$25 flat ($100 CA) / up to $25,000 · Closed Jan 23, 2023
More settlements people are checking
Payout status for other settlements we track, updated as administrators publish new information.