cyber
confidence high
sentiment negative
materiality 0.70
Uber discloses cybersecurity breach; attacker gained internal system access but no evidence of user data compromise
Uber Technologies, Inc
- An Uber contractor's account was compromised via a dark web password and MFA fatigue, giving the attacker access to internal tools.
- Attacker accessed Slack, HackerOne dashboard, and an internal finance tool; no evidence of accessing production systems or sensitive user data (credit cards, bank info, trip history).
- Uber rotated keys, locked codebase, blocked compromised accounts, and required re-authentication; customer services remained operational.
- Investigation ongoing with leading digital forensics firms; Uber is in coordination with the FBI and DOJ.
- The attacker is believed to be affiliated with the Lapsus$ hacking group, which has previously breached Microsoft, Cisco, and Nvidia.