Uber Hacked—18 Year Old Hacker Claims To Be Behind Extensive Breach
What has Uber said about the hack?
I reached out to Uber for a comment and was pointed to an official statement posted to Twitter which reads: "We are currently responding to a cybersecurity incident. We are in touch with law enforcement and will post additional updates here as they become available."
I have seen messages from someone who claims various Uber admin accounts are under their control. A New York Times reporter says that the hacker tells them he is 18 years old and hacked the Uber systems because "they had weak security." He further claims this was accomplished through the social engineering of an Uber employee to obtain login credentials.
Uber security vulnerability reports could have been stolen
Bleeping Computer has been in contact with the alleged hacker and has seen screenshots showing access to "critical Uber IT systems" that include security software, Amazon Web Services console, Google Workspace email admin dashboard and the aforementioned Slack server. It would also appear that the hacker gained access to Uber's HackerOne vulnerability bug bounty account, leaving comments on a number of report tickets. This could yet prove to be one of the most valuable resources from the attacker's perspective, as it has been claimed that Uber's vulnerability reports were downloaded. Marten Mickos, the HackerOne CEO, has stated that the Uber account has been locked down and the company is working with Uber to assist in the investigation.
"This attack has left Uber with a significant amount of data leaked with the potential of including customer and driver’s personal data," Jake Moore, global cyber security advisor at ESET, said. "This is seemingly the work of a clever socially engineered attack. Gaining entry to private data inside VPNs needs to be difficult and behind strict protections. This leaves Uber with a lot of questions about how much data was compromised via such an easy method."
It is not known what, if any, customer data might have been accessed at this point in time. This is a developing story, and I will keep updating it as more details emerge.
Follow me on Twitter or LinkedIn. Check out my website or some of my other work here.
No comments:
Post a Comment
WELCOME TO JOSHUALOADED BLOG
-------------------------
Please Take Note Of Our comment policy Below 👇👇👇
👉 Hi, Your feedback is very important to us.
👉 Please Do not post spam comments, it will be immediately removed upon our review.
👉 Please Avoid including website URLs in your comments.