Uber’s September 2022 incident did not start with a zero-day. According to Uber’s Newsroom security update on 19 September 2022, an EXT contractor’s Uber corporate password was likely purchased on the dark web after malware on a personal device exposed those credentials. The attacker then repeatedly tried to log in. Each attempt generated a two-factor login approval request that initially blocked access, until the contractor accepted one and a real workforce session was issued. Uber believes the attacker was affiliated with Lapsus$, the same group it said had hit Microsoft, Cisco, Samsung, Nvidia, and Okta that year.
That accepted push was the credential-phase failure. What followed inside Slack, G-Suite, and other internal tools was post-login abuse of an already-issued session, not another login ceremony.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did the attackers get into Uber in September 2022?
The Uber 2022 breach started with an EXT contractor account, not a production app exploit. According to Uber’s 19 September 2022 security update, the contractor’s Uber corporate password was likely purchased on the dark web after malware on a personal device exposed those credentials. The attacker then repeatedly tried to log in, generating two-factor login approval requests that initially blocked access, until the contractor accepted one and the attacker successfully logged in.
If the contractor had 2FA, how did MFA fatigue still work?
MFA fatigue worked on the Uber contractor login because the second factor was an approve/deny push on a known password. Uber stated the attacker repeatedly tried to log in and each attempt sent a two-factor login approval request. The prompts initially blocked access. Eventually the contractor accepted one, and the attacker received a legitimate session. Push MFA that can be spammed until a human taps Accept is still a transferable, coachable factor at login.
What could the attacker reach after the push was accepted?
After the Uber contractor login succeeded, the attacker accessed several other employee accounts that ultimately gave elevated permissions into internal tools including G-Suite and Slack. Uber reported the attacker posted to a company-wide Slack channel, reconfigured OpenDNS so some internal sites showed a graphic image, downloaded some Slack messages and finance-invoice-tool data, and viewed a HackerOne dashboard of already-remediated reports. Public reporting does not establish a complete inventory of every file taken from those tools.
Did the Uber 2022 attackers steal customer or trip data?
Uber reported no evidence that the attacker accessed production systems that power the apps, user accounts, or databases storing sensitive user information such as credit card numbers, bank account info, or trip history. Public-facing Uber, Uber Eats, and Uber Freight services stayed operational. Customer support was only minimally impacted while internal tools were taken down as a precaution. The documented blast was internal workforce systems, not production customer databases.
Was this the same Lapsus$ playbook seen elsewhere in 2022?
Uber stated it believes the attacker was affiliated with Lapsus$ and noted that in 2022 alone the group had breached Microsoft, Cisco, Samsung, Nvidia, and Okta, among others, typically with similar techniques. Uber also noted weekend reports that the same actor breached Rockstar Games. Public reporting does not establish an operational link between the Uber incident and Rockstar beyond that same-period attribution note in Uber’s update.