Close Menu
Beverly Hills Examiner

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Listen to Madonna and Kylie Minogue’s “Love Sensation (Afterhours Mix)”

    August 7, 2026

    Asia needs deeper energy markets if it’s going to achieve its AI ambitions

    August 7, 2026

    Chris Cuomo Tries to Play Dumb on DSA Radicals: ‘Who’s a Communist?’ (VIDEO)

    August 7, 2026
    Facebook X (Twitter) Instagram
    Beverly Hills Examiner
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    Beverly Hills Examiner
    Home»Technology»The Uber Hack’s Devastation Is Just Starting to Reveal Itself
    Technology

    The Uber Hack’s Devastation Is Just Starting to Reveal Itself

    By AdminSeptember 17, 2022
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    The Uber Hack’s Devastation Is Just Starting to Reveal Itself


    On Thursday evening, ride-share giant Uber confirmed that it was responding to “a cybersecurity incident” and was contacting law enforcement about the breach. An entity that claims to be an individual 18-year-old hacker took responsibility for the attack, bragging to multiple security researchers about the steps they took to breach the company. The attacker reportedly posted, “Hi @here I announce I am a hacker and Uber has suffered a data breach,” in a channel on Uber’s Slack on Thursday night. The Slack post also listed a number of Uber databases and cloud services that the hacker claimed to have breached. The message reportedly concluded with the sign-off, “uberunderpaisdrives.”

    The company temporarily took down access on Thursday evening to Slack and some other internal services, according to The New York Times, which first reported the breach. In a midday update on Friday, the company said that “internal software tools that we took down as a precaution yesterday are coming back online.” Invoking time-honored breach-notification language, Uber also said on Friday that it has “no evidence that the incident involved access to sensitive user data (like trip history).” Screenshots leaked by the attacker, though, indicate that Uber’s systems may have been deeply and thoroughly compromised and that anything the attacker didn’t access may have been the result of limited time rather than limited opportunity.

    “It’s disheartening, and Uber is definitely not the only company that this approach would work against,” says offensive security engineer Cedric Owens of the phishing and social engineering tactics the hacker claimed to use to breach the company. “The techniques mentioned in this hack so far are pretty similar to what a lot of red teamers, myself included, have used in the past. So, unfortunately, these types of breaches no longer surprise me.”

    The attacker, who could not be reached by WIRED for comment, claims that they first gained access to company systems by targeting an individual employee and repeatedly sending them multifactor authentication login notifications. After more than an hour, the attacker claims, they contacted the same target on WhatsApp pretending to be an Uber IT person and saying that the MFA notifications would stop once the target approved the login. 

    Such attacks, sometimes known as “MFA fatigue” or “exhaustion” attacks, take advantage of authentication systems in which account owners simply have to approve a login through a push notification on their device rather than through other means, such as providing a randomly generated code. MFA-prompt phishes have become more and more popular with attackers. And in general, hackers have increasingly developed phishing attacks to work around two-factor authentication as more companies deploy it. The recent Twilio breach, for example, illustrated how dire the consequences can be when a company that provides multifactor authentication services is itself compromised. Organizations that require physical authentication keys for logins have had success defending themselves against such remote social engineering attacks.

     The phrase “zero trust” has become a sometimes meaningless buzzword in the security industry, but the Uber breach seems to at least show an example of what zero trust is not. Once the attacker had initial access inside the company, they claim they were able to access resources shared on the network that included scripts for Microsoft’s automation and management program PowerShell. The attackers said that one of the scripts contained hard-coded credentials for an administrator account of the access management system Thycotic. With control of this account, the attacker claimed, they were able to gain access tokens for Uber’s cloud infrastructure, including Amazon Web Services, Google’s GSuite, VMware’s vSphere dashboard, the authentication manager Duo, and the critical identity and access management service OneLogin.





    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleThe World Has Reached Peak Attenborough
    Next Article TUCKER CARLSON: Why is Ron DeSantis a human trafficker and not Joe Biden?

    RELATED POSTS

    One of China’s Most Powerful AI Models Has Also Escaped Containment

    August 7, 2026

    eBay continues to bet on live shopping after record quarter

    August 6, 2026

    OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree

    August 6, 2026

    Trump EPA wrongly canceled $20B in climate funds, appeals court rules

    August 5, 2026

    OK, Well, Rogue AI Agents Are Hacking Again

    August 5, 2026

    Apple says more ex-employees may have taken confidential data to OpenAI

    August 4, 2026
    latest posts

    Listen to Madonna and Kylie Minogue’s “Love Sensation (Afterhours Mix)”

    It was the WorldPride Amsterdam appearance heard ’round the world: Kylie Minogue strutting onstage to…

    Asia needs deeper energy markets if it’s going to achieve its AI ambitions

    August 7, 2026

    Chris Cuomo Tries to Play Dumb on DSA Radicals: ‘Who’s a Communist?’ (VIDEO)

    August 7, 2026

    Aces star targets heckling Fever fans in Indy before Chelsea Gray stuns Caitlin Clark in OT thriller

    August 7, 2026

    One of China’s Most Powerful AI Models Has Also Escaped Containment

    August 7, 2026

    OpenAI’s latest math breakthroughs commit research misconduct, experts say

    August 7, 2026

    Prime Video’s New R-Rated Bosch Replacement Is Ballard’s Perfect Rival

    August 7, 2026
    Categories
    • Books (1,410)
    • Business (6,314)
    • Cover Story (9)
    • Film (6,253)
    • Lifestyle (4,313)
    • Music (6,324)
    • Politics (6,296)
    • Science (5,663)
    • Technology (6,248)
    • Television (5,944)
    • Uncategorized (3)
    • US News (6,299)
    popular posts

    Vince McMahon Retires — Read His Statement

    Vince McMahon announced today he was retiring as chairman and CEO of WWE. The news…

    Jen Shah: The Real Housewives of Salt Lake City Star Still Filming Despite Guilty Plea

    July 12, 2022

    FaZe Clan’s essential FaZe1 Live series gear

    June 15, 2022

    Classic Pieces That Should Be In Every Man’s Winter Wardrobe

    October 30, 2024
    Archives
    Browse By Category
    • Books (1,410)
    • Business (6,314)
    • Cover Story (9)
    • Film (6,253)
    • Lifestyle (4,313)
    • Music (6,324)
    • Politics (6,296)
    • Science (5,663)
    • Technology (6,248)
    • Television (5,944)
    • Uncategorized (3)
    • US News (6,299)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    OpenAI’s latest math breakthroughs commit research misconduct, experts say

    August 7, 2026

    Prime Video’s New R-Rated Bosch Replacement Is Ballard’s Perfect Rival

    August 7, 2026

    ’90 Day Fiance’ Brandan & Mary DeNuccio Beg For More Money

    August 7, 2026
    © 2026 Beverly Hills Examiner. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT