Skip to content
NetarxImpact Database
MFA Fatigue / Push BombingNo AI reportedConfirmed

Uber breached after MFA push bombing and a WhatsApp message posing as IT

Uber Technologies · Transportation & Logistics · United States · September 15, 2022

What happened

In September 2022 an attacker obtained the account of an Uber external contractor, whose password had likely been purchased from a dark web marketplace after being stolen by malware. The attacker repeatedly triggered MFA push approvals and then contacted the contractor on WhatsApp posing as Uber IT support, telling them to accept the prompt to stop the notifications. Once inside, the attacker reached Uber's internal Slack, VPN, and administrative consoles and posted a message announcing the breach.

How the deception worked

With a valid password in hand but no second factor, the attacker sent a stream of login requests that generated push notifications on the contractor's phone for over an hour. When the target did not approve, the attacker messaged them on WhatsApp claiming to be from Uber IT and said the notifications would stop if they accepted one. The contractor did. Inside the network the attacker found a PowerShell script on a network share containing hard-coded privileged credentials for a privileged access management system, which unlocked secrets for further internal services including Slack, cloud consoles and internal dashboards.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Number-matched or key-based MFA removes the blind approve button, and secrets stored in scripts should live in a vault so one identity compromise does not become domain-wide privilege.

Sources (5)

  1. Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack
    Dark Reading·darkreading.comOpen ↗
  2. Lessons to learn from the Uber security breach
    KPMG·assets.kpmg.comOpen ↗
  3. Detecting Scatter Swine: Insights into a Relentless Phishing Campaign
    Okta Security·sec.okta.comOpen ↗
  4. Security Update
    Uber·uber.comOpen ↗
  5. Uber links breach to Lapsus$ group, blames contractor for hack
    BleepingComputer·bleepingcomputer.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.