> The database included the drivers’ license numbers for approximately 600,000 people who drove for Uber.
Drivers licenses are deterministic and can be generated by knowing full name and DOB and state. They aren't PII.
> The database included the drivers’ license numbers for approximately 600,000 people who drove for Uber.
Drivers licenses are deterministic and can be generated by knowing full name and DOB and state. They aren't PII.
> "During this time, two hackers contacted Sullivan by email and demanded a six-figure payment in exchange for silence. The hackers ultimately revealed that they had accessed and downloaded an Uber database containing personally identifying information, or PII, associated with approximately 57 million Uber users and drivers."
The hackers were demanding a ransom from Uber to keep silent about a data breach. Which is a whole lot different than paying a ransom to decrypt valuable, internal data. If a company has been breached, while it will almost certainly cause damage fiscally & to their reputation- they have a responsibility to notify users/customers. I'm unfamiliar with the law on this, but it should be illegal for a company to pay a ransom for malicious actors to keep silent about data they stole.
That those ids are often formed from a transparent function of other PII only makes the issue more extreme. It's like PII^2.
Furthermore, data being derived from something else has no bearing on whether it’s PII or not. ID numbers are personally identifiable information by definition. The whole point of them is to personally identify someone.