Home/Incidents/Uber

Uber

15 Sep 2022 · National · Transport & Logistics
Other CRITICAL ✓ Verified

What happened

A teenage hacker affiliated with the Lapsus$ group bought leaked credentials on the dark web and used a persistent MFA fatigue loop to compromise an internal employee. The adversary achieved absolute administrative access to Uber's AWS, Google Cloud Workspace, Slack channels, and HackerOne corporate portals.

Incident details

Organisation
Uber
Date
15 Sep 2022
Attack type
Other
Severity
CRITICAL
Sector
Transport & Logistics
State
National
Records affected
Unknown
Threat actor
Lapsus$

Source

itnews.com.au ↗
← Back to all incidents