secwatch.observer — SEC 8-K summary ====================================== Issuer: Uber Technologies, Inc (UBER) CIK: 0001543151 Form: 8-K Filed at: 2022-09-19T23:59:59+00:00 Accession: 0001552781-22-000558 Event type: cyber Sentiment: negative Materiality: 0.70 Item codes: 7.01, 9.01 LLM model: deepseek-v4-flash:cloud@v2 Uber discloses cybersecurity breach; attacker gained internal system access but no evidence of user data compromise -------------------------------------------------------------------------------- - An Uber contractor's account was compromised via a dark web password and MFA fatigue, giving the attacker access to internal tools. - Attacker accessed Slack, HackerOne dashboard, and an internal finance tool; no evidence of accessing production systems or sensitive user data (credit cards, bank info, trip history). - Uber rotated keys, locked codebase, blocked compromised accounts, and required re-authentication; customer services remained operational. - Investigation ongoing with leading digital forensics firms; Uber is in coordination with the FBI and DOJ. - The attacker is believed to be affiliated with the Lapsus$ hacking group, which has previously breached Microsoft, Cisco, and Nvidia. Source: EDGAR index: https://www.sec.gov/Archives/edgar/data/1543151/000155278122000558/0001552781-22-000558-index.htm Primary doc: https://www.sec.gov/Archives/edgar/data/1543151/000155278122000558/e22427_uber-8k.htm HTML page: https://secwatch.observer/filing/0001552781-22-000558 License: Source filings: public domain (SEC EDGAR). Summaries (headline + bullets): CC-BY-4.0; attribute https://secwatch.observer