LIVE · cybersecurity feed
Live wire
Australia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning RepairCISA’s logging guidance works beyond government
ai

When the Algorithm Fires You: Uber Faces €825M Fine

Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or cookie consent. The regulator imposed an 825 million euro penalty, roughly $964 million, over […]

zeroday.news ·

Uber is facing an €825 million (approximately $964 million) fine from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) for its use of fully automated systems to suspend or deactivate driver accounts without human review. The AP ruled that Uber violated the General Data Protection Regulation (GDPR) by making significant decisions affecting individuals' livelihoods solely through algorithms, and by failing to adequately inform drivers about these automated processes.

The fine specifically addresses Uber's practices between 2018 and 2022. During this period, Uber's software monitored driver behavior and customer reviews. If the system detected suspected fraud or consistently low customer ratings, driver accounts were automatically deactivated, either temporarily or permanently, leading to a loss of income. The AP emphasized that these decisions were made without any human assessment or oversight.

Under GDPR, fully automated decisions that can significantly impact a person's life are restricted, particularly if they remove an individual's ability to earn a living without human intervention. The regulation also mandates that companies disclose when automated systems are used to make such decisions. The AP found Uber deficient on both counts.

Uber has stated its intention to appeal the decision and the size of the fine. The company claims that the regulator's examination focused on outdated policies and systems that have since been discontinued. Uber also asserts that it takes decisions affecting driver income seriously and has implemented human reviews, safeguards, and an appeals process for drivers. The appeal is expected to clarify whether these protections were in place during the period covered by the fine or were introduced later.

This is not the first time Uber has faced penalties from Dutch regulators. It marks the fourth fine imposed by the AP on Uber. A previous significant fine of €290 million in 2024 concerned the transfer of European drivers' personal data to the United States without adequate protections, a decision Uber also appealed.

The case highlights a broader issue within the gig economy, where many platforms rely on algorithms for managing workers, routes, and account statuses. The ruling underscores the potential costs for companies that depend on automated decisions without sufficient human oversight, signaling that simply attributing decisions to "the algorithm" is no longer acceptable under EU law when individuals' livelihoods are at stake.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek.

security

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.

ddos

Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack

Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, […]

security

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.

patch

You could've applied all 1,449 Oracle patches and still been hit by this attack

Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert

ddos

Massive DDoS attack disrupts Norway’s government digital services

A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]