{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:35.403Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Uber breached after MFA push bombing and a WhatsApp message posing as IT","date":"2022-09-15","date_precision":"day","victim_org":"Uber Technologies","sector":"Transportation & Logistics","country":"United States","primary_vector":"MFA Fatigue / Push Bombing","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft","Insider Access","Service Disruption"],"loss_usd":null,"loss_note":"No monetary loss disclosed; Uber said no public-facing systems or user accounts were accessed.","records_affected":null,"threat_actor":"Lapsus$ (an 18-year-old member was later convicted in the UK)","summary":"In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.","how_it_worked":"With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.","lessons":"Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.","confidence":"Confirmed","sources":[{"title":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack","url":"https://www.darkreading.com/cyberattacks-data-breaches/uber-breach-external-contractor-mfa-bombing-attack","publisher":"Dark Reading"},{"title":"Lessons to learn from the Uber security breach","url":"https://assets.kpmg.com/content/dam/kpmgsites/in/pdf/2022/09/27-september-2022-lessons-to-learn-from-the-uber-security-breach.pdf.coredownload.inline.pdf","publisher":"KPMG"},{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Security Update","url":"https://www.uber.com/newsroom/security-update/","publisher":"Uber"},{"title":"Uber links breach to Lapsus$ group, blames contractor for hack","url":"https://www.bleepingcomputer.com/news/security/uber-links-breach-to-lapsus-group-blames-contractor-for-hack/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-uber-breached-after-mfa-push-bombing-and-a-whatsapp-message-posing-as-it"}]}