What happened
In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.
How the deception worked
With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.
Sources (5)
- Uber: Lapsus$ Targeted External Contractor With MFA Bombing AttackDark Reading·darkreading.comOpen ↗
- Lessons to learn from the Uber security breachKPMG·assets.kpmg.comOpen ↗
- Detecting Scatter Swine: Insights into a Relentless Phishing CampaignOkta Security·sec.okta.comOpen ↗
- Security UpdateUber·uber.comOpen ↗
- Uber links breach to Lapsus$ group, blames contractor for hackBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.