Uber reveals more on recent hack, says Lapsus$ is to blame

Uber has introduced WA2R in Delhi
(Image credit: Uber)

Uber has shared more details on its recent data breach, sharing details on how it happened, what the impact was, and who it thinks was (most likely) to blame.

In a security update, Uber said a threat actor purchased an Uber EXT contractor’s login credentials from the dark web, and managed to log into the account after the contractor accepted a two-factor login request from the secondary endpoint

From there, the attacker accessed “several other employee accounts” (Uber does not go into details on how this happened), which gave them elevated permissions to a couple of tools, including Google Workspace and Slack. 

Slack and invoices

Although the group is yet to take responsibility for the attack, Uber has laid the blame on Lapsus$, a known extortion group that’s previously breached the likes of Microsoft, Cisco, Samsung, Nvidia, and Okta.

Uber claims that the impact of the attack was limited, as while the attacker accessed several internal systems, they weren't able to access production systems that power Uber’s apps. User accounts were safe, as well as the database holding sensitive user information (credit card numbers, bank account info, trip history). Even if the attacker managed to access credit card data or personal health data, this data is encrypted, the company says.

Furthermore, the attackers made no changes to Uber’s codebase. Customer and user data stored by cloud providers was not tampered with, either. However, internal Slack messages, as well as data from a tool used to manage invoices, have been taken. 

When news of the data breach first broke, security researchers and the media were focused on the fact that the attackers accessed Uber’s dashboard at HackerOne, as that would give them insights into various vulnerabilities the company has, possibly including those that are yet to be fixed. 

When news of the data breach first broke, security researchers and the media were focused on the fact that the attackers accessed Uber’s dashboard at HackerOne, as that would give them insights into various vulnerabilities the company has, possibly including those that are yet to be fixed. 

That would open the doors for a number of different cyberattacks. However, Uber now says any bug reports the attackers accessed have been fixed. 

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
GrubHub app on a mobile phone
GrubHub reveals massive data breach - customers, drivers, businesses all affected, here's what we know
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
Password
Millions of airline customers possibly affected by OAuth security flaw
Avast cybersecurity
Zapier tells customers their data may have been accessed
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Latest in Security
person at a computer
Many workers are overconfident at spotting phishing attacks
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Latest in News
Star Wars Knights of the Old Republic
Knights of the Old Republic remake developer Saber Interactive states all its projects are 'still in development'
Circular smart ring
Circular's new smart ring is getting blood pressure and blood glucose monitoring before the Apple Watch
Gemini on a mobile phone.
Worryingly, Google Gemini’s new AI image generation features can be used to remove watermarks from images and I'm concerned
iPad mini 2021
Huawei might have beaten Apple to the folding phone finish line by creating a foldable 'iPad mini'
Google Pixel 9 in green Wintergreen color showing AI features on screen
Multiple hands-on Google Pixel 9a videos have emerged, days ahead of the likely launch
A man getting angry with his laptop.
Windows 11 bug deletes Copilot from the OS – is this the first glitch ever some users will be happy to encounter?