Inside Uber’s Data Scandals
In my last article I found out that the topic of data at Uber is so big that it deserves its own article. Here you go!
If you open the Uber app, you aren’t just looking at a map, you’re looking at a breathing mathematical model. For Uber, data isn’t just a “business asset”, it is the literal oxygen of the company. Without it, the cars stop, the prices break, and the system collapses into chaos.
As the company moves further, the “Magic of Uber” has shifted from simply finding a ride to orchestrating a massive, multi-vertical ecosystem of mobility, delivery, and advertising.
Here is how data fuels the world’s most famous “logistics company that owns no vehicles.”
The Invisible Engine: How Data Actually Runs Uber
The Michelangelo of Algorithms
At the heart of Uber’s data empire is Michelangelo, an internal Uber's Machine Learning-as-a-Service (MLaaS) platform, designed to democratise AI and make scaling machine learning as easy as requesting a ride. While it started in 2015 (under leadership of Travis Kalanick) by predicting ETAs (Estimated Time of Arrival), it now handles everything from GenAI-driven customer support to detecting fraudulent “phantom” rides. As of 2026, Michelangelo manages over 400 active ML projects and more than 5,000 models in production. At peak times, it serves roughly 10 million real-time predictions per second.
And connected to it Hyper-Local Demand Prediction. Uber’s ability to tell a driver where to go before a rider even requests a trip is uncanny. Uber’s ML systems ingest historical data and real-time signals to predict demand at a hyper-local level, sometimes even down to specific city blocks. The models don’t just look at Uber data; they factor in weather patterns, local concerts, flight delays, and even public transit strikes to anticipate a spike in demand before it happens.
Surge Pricing: The “Relief Valve”
Most people (including myself) hate surge pricing, but from a data perspective, it is a masterpiece of economic equilibrium. Since its introduction in late 2011 under leadership of Travis Kalanick Uber treats its marketplace like a liquid.
Surge isn’t just “more people = more money.” The algorithm recalculates every five minutes based on the cross-correlation between supply, demand, and Estimated Wait Times (EWT). It’s a “relief valve.” By increasing the price, the system simultaneously encourages more drivers to head toward a busy zone while filtering out riders who aren’t in a rush. This ensures that the person who really needs a ride can always get one.
Data-Driven Advertising
In 2026, Uber is proving that it’s not just a taxi service, but an advertising giant. Because Uber knows exactly where you are and where you’re going, it possesses “high-intent” data that Google and Meta can only dream of.
Example: If you’re taking an Uber to a French restaurant, the app might show you an ad for a specific wine or a nearby dessert shop.
Uber’s goal for 2026 is to scale this advertising without “breaking the vibe.” The data ensures that ads feel like helpful suggestions (relevance) rather than intrusive clutter.
Controversies
Alongside these developments, it’s also important to mention several controversies, unethical projects, and data breaches. Most of them took place during the time Uber was led by Travis Kalanick, a highly complicated and complex figure, I wrote about previously.
The God View
In the early days of Uber, “God View” wasn’t just a cool name, it was a literal, real-time map of every single person using the app.
Think of it as a video game interface for the real world. From a laptop, an Uber employee could see a “ghost” icon for every car on the road and click on it to see exactly who was inside.
The “Wild West” Strategy: At the time, Uber’s strategy was “growth at any cost.” God View was technically built to help managers track car supply, but it quickly became the ultimate insider party trick. The Creep Factor is that executives reportedly used it to track journalists’ locations in real-time or show off the travel habits of celebrities at launch parties. There were almost no internal locks. If you worked at Uber, you could basically stalk your ex or a high-profile politician just by opening your laptop.
The “God View” era eventually crashed into reality. After a series of privacy scandals and investigations by the FTC, Uber was forced to lock down the tool, rename it “Heaven View,” and submit to 20 years of privacy audits.
It remains the ultimate case study of what happens when a tech company’s data power grows way faster than its ethics.
The Greyball
While God View was about spying on riders, Greyball was about hiding from the law.
If God View was a “video game” for the office, Greyball was a stealth mode designed to trick government officials trying to catch Uber operating illegally.
The “Ghost Map” Strategy
In cities where Uber wasn’t yet legal (like Portland or Seoul), police would try to hail a ride to impound the car or ticket the driver. Uber’s solution? A secret software tool called Greyball.
Here’s how it worked. Identifying the “Enemy”: Uber used data to spot undercover stings. If someone opened the app near a government building or used a credit card linked to a police union, they were “Greyballed.” When a Greyballed official opened Uber, they didn’t see a real map. They saw a fake version of the app populated with “ghost cars” that didn’t exist. If they actually tried to book a ride, the app would either show no cars available or simply cancel the request instantly. The driver never even knew the “sting” was happening.
Uber’s strategy was “Ask for forgiveness, not permission.” By using Greyball, they could launch in a city, build a massive fan base of riders, and stay one step ahead of regulators until the laws were eventually changed in their favor.
The New York Times exposed the program in 2017, sparking federal investigations. Uber eventually banned the use of Greyball to dodge local regulators, but it remains the ultimate example of weaponized code.
And that is not all!
The Hell
If God View was about watching riders and Greyball was about dodging the law, then “Hell” was about destroying the competition. I’ve already outlined in my last article what Uber did to Lyft, but the Hell was only slightly mentioned. Here is more about it.
While the other tools were defensive or internal, Hell was pure corporate espionage. It was a secret program designed specifically to stalk, target, and poach drivers from Uber’s arch-rival, Lyft.
The “Spyware” Strategy
Uber didn’t just want to know where its own cars were, it wanted to know where Lyft’s were, too. Between 2014 and 2016, they built a “ghost” system to infiltrate Lyft’s app. Uber created thousands of fake Lyft rider accounts and spread them across a city in a “grid”. These fake accounts tricked Lyft’s system into showing the locations of the eight nearest drivers. By comparing this data with their own internal maps, Uber could identify “double-app” drivers, the people working for both platforms at the same time.
The “Hellish” Playbook
Once Uber knew which drivers were flirting with the competition, they moved in for the kill: Uber would send special bonuses and ride offers specifically to those “double-app” drivers to keep them busy on the Uber platform. The goal was to dry up the supply of Lyft drivers. If all the drivers were busy with Uber, Lyft’s wait times would skyrocket, and their customers would eventually switch to Uber out of frustration.
The program earned its name because it was the “flip side” to the Heaven (God View) program. It was so top-secret that even most Uber city managers didn’t know where their competitive data was coming from.
When the program was exposed in 2017, it triggered an FBI investigation and multiple class-action lawsuits for unfair business practices and computer fraud.
Hell is the ultimate example of Uber’s early “win at all costs” era, where the code wasn’t just built to help you find a ride, but to make sure you couldn’t find one anywhere else.
When the Data Engine Failed
There’s a familiar pattern in tech: move fast, scale aggressively, and worry about the consequences later. In its early years, Uber followed that script, and when it came to data protection, the consequences were real.
2014: The First Major Incident
In May 2014, an attacker used an access key found on a public GitHub repository to enter Uber’s Amazon Web Services (AWS) server. The names and driver’s license numbers of approximately 50,000 to 100,000 drivers were accessed. Uber didn’t discover the breach immediately and only disclosed it to the public in February 2015. 9 months later!!! Cringe, right?
But that was only a preview.
2016: The “Great Cover-Up”
In October 2016, hackers again used stolen credentials from a GitHub repository to access Uber’s AWS servers. This was massive, 57 million users and drivers had their data stolen, including names, email addresses, phone numbers, and driver’s license numbers. Instead of reporting the breach to the authorities, Uber’s security team paid the hackers $100,000 through a bug bounty program to delete the data and stay quiet.
The CEO at the time, the notorious Travis Kalanick, didn’t even have the guts to disclose the breach. The public didn’t find out until the new CEO, Dara Khosrowshahi, revealed the truth in November 2017. This led to massive fines ($148 million) and criminal charges against the former Chief Security Officer.
Following the change in leadership, Uber began to treat its previous security failures as a roadmap for improvement. While data incidents haven't vanished entirely, they have become far less frequent and have shifted in nature. Rather than attackers breaking directly into Uber’s primary "vault," more recent vulnerabilities have originated from "secondary" leaks, usually involving a breach at a third-party vendor or a clever social engineering trick that targets a single human employee rather than the system's core infrastructure.
2022: The “MFA Fatigue” Attack
In September 2022, a hacker (linked to the Lapsus$ group) gained access to Uber’s internal network through a social engineering trick called “MFA Fatigue.” After stealing a contractor’s password, the hacker sent constant login approval requests to their phone. The contractor eventually clicked “Approve” out of frustration. The hacker gained access to Uber’s internal Slack messages, Google Workspace, and cloud environments. While internal systems were “fully compromised,” Uber stated that no customer trip history or credit card details were stolen.
2022/2023: The Teqtivity Third-Party Leak
Shortly after the MFA attack, a separate leak occurred via Teqtivity, a third-party vendor Uber used to manage its IT assets (like laptops). Data belonging to roughly 77,000 Uber employees was leaked on a hacking forum, including company email addresses and mobile device info. Again, customer data was not affected, but it highlighted the risk of “third-party” vendors in Uber’s ecosystem.
As of today in May 2026, there have been no major new reports of customer data being leaked this year. However, the company remains a “tier-one” target for hackers because of the sheer volume of data I discussed in the article, specifically the high-intent location and payment data they hold.
Uber’s current strategy focuses on “Zero Trust” security model, essentially trying to train their thousands of employees to spot the social engineering tricks that caused their past headaches.
Closing
I hope you enjoyed reading this deep dive into Uber’s data ecosystem, controversies, and the decisions that shaped Uber. But the story is far from over.
In my next story, I’ll shift the focus from Uber’s past to its future. The big question is no longer whether Uber can dominate ride-sharing, it’s whether the company can survive the next technological shift. With autonomous driving advancing rapidly, competitors like Waymo and Tesla are positioning themselves to potentially reshape the entire transportation industry.
Could self-driving technology make Uber stronger? Or could it slowly turn the company into a middleman with shrinking influence and margins? And what happens if companies controlling the autonomous vehicles no longer need Uber at all?
If you found this article insightful, I’d really appreciate your support:
leave a comment with your thoughts or disagreements,
share the article with others interested in tech and business,
restack it so more readers can discover it,
and hit the like button if you want to see more deep dives like this one.
Your support genuinely helps independent writing grow and it helps me continue producing detailed stories like this.
See you in the next article.




