Uber confirms it was hit by major cyberattack


Taxi giant Uber has suffered a major cyberattack in which threat actors accessed many of the company’s critical IT systems, applications, endpoints (opens in new tab), and sensitive data.
The attack, which has since been confirmed by Uber, appears to be the work of a threat actor managed to steal login credentials from a company employee.
The New York Times, which broke the news, said it had spoken to the alleged hacker, who claimed to have breached Uber after performing a social engineering attack on an employee and stealing passwords.
Stealing vulnerability reports
“We are currently responding to a cybersecurity incident. We are in touch with law enforcement and will post additional updates here as they become available,” Uber confirmed via its support Twitter account (opens in new tab).
It’s not known if any viruses or malware were used, but using the stolen credentials, the attackers were able to gain access to a treasure trove of sensitive data, including internal systems, email dashboard, Slack server, security software, Windows domain, Amazon Web Services console, VMware ESXi virtual machines, and the Google Workspace email admin dashboard.
While all of this data is valuable, the attackers may have hit the jackpot with vulnerability reports.
A source told BleepingComputer the threat actor “downloaded all vulnerability reports” before losing access to Uber’s bug bounty program. In other words, the hackers obtained all of the information regarding bugs and flaws that Uber might be having/fixing at the moment.
Uber runs a bug bounty program via HackerOne, allowing security researchers to share their findings on Uber’s software bugs and vulnerabilities, in private, and get paid for it. This program has since been disabled by HackerOne, but it might just be a little too late.
This is not the first time Uber has faced a major data incident. Earlier in 2022, the company admitted to covering up a major data breach that took place in 2016. That data breach resulted in user data making its way online, and with a couple of executives trying to cover the whole thing up.
Uber’s confession came as part of a settlement that saw it avoid criminal prosecution from the U.S. Department of Justice.
Via: BleepingComputer (opens in new tab)
Audio player loading… Taxi giant Uber has suffered a major cyberattack in which threat actors accessed many of the company’s critical IT systems, applications, endpoints (opens in new tab), and sensitive data. The attack, which has since been confirmed by Uber, appears to be the work of a threat actor…
Recent Posts
- An obscure French startup just launched the cheapest true 5K monitor in the world right now and I can’t wait to test it
- Google Meet’s AI transcripts will automatically create action items for you
- No, it’s not an April fool, Intel debuts open source AI offering that gauges a text’s politeness level
- It’s clearly time: all the news about the transparent tech renaissance
- Windows 11 24H2 hasn’t raised the bar for the operating system’s CPU requirements, Microsoft clarifies
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010