Uber Says It’s Investigating a Potential Breach of Its Computer Systems

Share:

Ride hailing giant Uber disclosed Thursday it’s responding to a cybersecurity incident involving a breach of its network and that it’s in touch with law enforcement authorities.

The New York Times first reported the incident. The company pointed to its tweeted statement when asked for comment on the matter.

 

The hack is said to have forced the company to take its internal communications and engineering systems offline as it investigated the extent of the breach.

The publication said the malicious intruder compromised an employee’s Slack account, and leveraged it to broadcast a message that the company had “suffered a data breach,” in addition to listing internal databases that’s supposed to have been compromised.

“It appeared that the hacker was later able to gain access to other internal systems, posting an explicit photo on an internal information page for employees,” the New York Times said.

Uber has yet to offer additional details about the incident, but it seems that the hacker, believed to be an 18-year-old teenager, social-engineered the employee to get hold of their password by masquerading as a corporate IT person and used it to obtain a foothold into the internal network.

One interesting aspect is that the attacker was able to bypass the account’s two-factor authentication (2FA) protections by spamming the employee with push alerts and also contacted the individual on WhatsApp to comply with the authorization by claiming to be from Uber’s IT department.

The technique is reminiscent of the recently disclosed Cisco hack wherein the cybercriminal actors resorted to the technique of prompt bombing to achieve a 2FA push acceptance.

“Once on the internal network, the attackers found high privileged credentials laying on a network file share and used them to access everything, including production systems, corp EDR console, [and] Uber slack management interface,” Kevin Reed, chief information security officer at Acronis, told The Hacker News.

This is not Uber’s first breach. It came under scrutiny for failing to properly disclose a 2016 data breach affecting 57 million riders and drivers, and ultimately paying off the hackers $100,000 to hide the breach. It became public knowledge only in late 2017.

Federal prosecutors in the U.S. have since charged its former security officer, Joe Sullivan, with an alleged attempted cover-up of the incident, stating he had “instructed his team to keep knowledge of the 2016 breach tightly controlled.” Sullivan has contested the accusations.

 

In December 2021, Sullivan was handed down additional three counts of wire fraud to previously filed felony obstruction and misprision charges. “Sullivan allegedly orchestrated the disbursement of a six-figure payment to two hackers in exchange for their silence about the hack,” the superseding indictment said.

It further said he “took deliberate steps to prevent persons whose PII was stolen from discovering that the hack had occurred and took steps to conceal, deflect, and mislead the U.S. Federal Trade Commission (FTC) about the data breach.”

The latest breach also comes as the criminal case against Sullivan went to trial in the U.S. District Court in San Francisco.

“The compromise is certainly bigger compared to the breach in 2016,” Reed said. “Whatever data Uber keeps, the hackers most probably already have access.”

https://thehackernews.com/2022/09/uber-says-its-investigating-potential.html?

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:44 am, May 24, 2025
weather icon 13°C
L: 12° | H: 14°
moderate rain
Humidity: 87 %
Pressure: 1014 mb
Wind: 8 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 1.78 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:56 am
Sunset: 8:58 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
12° | 14°°C 1 mm 100% 13 mph 94 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 20°°C 0.93 mm 93% 16 mph 90 % 1015 mb 0 mm/h
Mon May 26 10:00 pm
weather icon
10° | 17°°C 1 mm 100% 13 mph 79 % 1018 mb 0 mm/h
Tue May 27 10:00 pm
weather icon
13° | 20°°C 1 mm 100% 14 mph 91 % 1017 mb 0 mm/h
Wed May 28 10:00 pm
weather icon
14° | 21°°C 1 mm 100% 16 mph 97 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
13° | 13°°C 1 mm 100% 10 mph 90 % 1014 mb 0 mm/h
Today 10:00 am
weather icon
15° | 16°°C 0.24 mm 24% 10 mph 94 % 1013 mb 0 mm/h
Today 1:00 pm
weather icon
22° | 22°°C 0 mm 0% 13 mph 61 % 1012 mb 0 mm/h
Today 4:00 pm
weather icon
24° | 24°°C 0 mm 0% 13 mph 54 % 1011 mb 0 mm/h
Today 7:00 pm
weather icon
19° | 19°°C 0.43 mm 43% 9 mph 77 % 1011 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 11 mph 88 % 1010 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 15°°C 0 mm 0% 12 mph 85 % 1009 mb 0 mm/h
Tomorrow 4:00 am
weather icon
15° | 15°°C 0.93 mm 93% 15 mph 90 % 1007 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€95,141.52
-2.69%
Ethereum(ETH)
€2,243.68
-6.01%
Tether(USDT)
€0.88
0.01%
XRP(XRP)
€2.05
-5.39%
Solana(SOL)
€154.29
-4.91%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.201614
-8.54%
Shiba Inu(SHIB)
€0.000013
-8.14%
Pepe(PEPE)
€0.000012
-11.19%
Peanut the Squirrel(PNUT)
€0.311130
-11.09%
Scroll to Top