{"id":6223,"date":"2022-09-18T20:15:32","date_gmt":"2022-09-18T19:15:32","guid":{"rendered":"http:\/\/roglacup.com\/klaus62\/?p=6223"},"modified":"2022-09-18T20:31:42","modified_gmt":"2022-09-18T19:31:42","slug":"uber-investigating-cybersecurity-incident-after-hacker-breaches-its-internal-network-techcrunch","status":"publish","type":"post","link":"https:\/\/roglacup.com\/klaus62\/2022\/09\/18\/uber-investigating-cybersecurity-incident-after-hacker-breaches-its-internal-network-techcrunch\/","title":{"rendered":"Uber investigating cybersecurity incident after hacker breaches its internal network| TechCrunch"},"content":{"rendered":"<div class=\"container__access-control\">\n<div class=\"ad-unit ad-leaderboard-article ad-size-y-250\">\n<div>\n<div id=\"tc-ad-leaderboard-article-2400114\" class=\"ad-unit__ad ad-unit__leaderboard\">\n<div id=\"jacPosition_leaderboard-article-2400114\" class=\"jac-container\">\u00a0<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"article__content-outer\">\n<div class=\"article__floating-wrap\">\n<div class=\"article__social-vertical-share article__social-vertical-share-- vertical-share--visible vertical-share--open\">\n<div class=\"copied-indicator\">\u00a0<\/div>\n<\/div>\n<\/div>\n<div>\n<div class=\"article__content-wrap\">\n<div class=\"article-content\">\n<p id=\"speakable-summary\">Uber confirmed on Thursday that it\u2019s responding to a cybersecurity incident after reports claimed a hacker had breached its internal network.<\/p>\n<p>The ride-hailing giant discovered the breach on Thursday and has taken several of its internal communications and engineering systems offline while it investigates the incident, according to a\u00a0<a href=\"https:\/\/www.nytimes.com\/2022\/09\/15\/technology\/uber-hacking-breach.html\" target=\"_blank\" rel=\"noopener\">report by The New York Times<\/a>, which broke news of the breach.<\/p>\n<p>Uber said in a statement given to TechCrunch that it\u2019s investigating a cybersecurity incident and is in contact with law enforcement officials, but declined to answer additional questions.<\/p>\n<div class=\"container__access-control\">\n<div id=\"tc-ad-tc-target-mid-article-2400114\" class=\"ad-unit__ad ad-unit__native_midarticle\">\n<div id=\"jacPosition_tc-target-mid-article-2400114\" class=\"jac-container\">\n<div>\u00a0<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>The sole hacker behind the beach, who claims to be 18 years old, told the Times that he compromised Uber because the company had weak security. The attacker reportedly used social engineering to compromise an employee\u2019s\u00a0<a href=\"https:\/\/techcrunch.com\/tag\/slack\/\">Slack<\/a>\u00a0account, persuading them to hand over a password that allowed them access to Uber\u2019s systems.\u00a0This has become a popular tactic in recent attacks against well-known companies, including\u00a0<a href=\"https:\/\/techcrunch.com\/2022\/08\/25\/twilio-hackers-group-ib\/\">Twilio<\/a>,\u00a0<a href=\"https:\/\/techcrunch.com\/2022\/04\/04\/mailchimp-internal-tool-breach\/\">Mailchimp\u00a0<\/a>and\u00a0<a href=\"https:\/\/techcrunch.com\/2022\/03\/23\/okta-breach-sykes-sitel\/\">Okta<\/a>.<\/p>\n<p>Shortly before the Slack system was taken offline on Thursday afternoon, Uber employees received a message that read, \u201cI announce I am a hacker and Uber has suffered a data breach,\u201d the Times reports. The hacker also reportedly said that Uber drivers should receive higher pay.<\/p>\n<div class=\"embed breakout\">\n<div class=\"twitter-tweet twitter-tweet-rendered\"><iframe id=\"twitter-widget-0\" class=\"\" title=\"Twitter Tweet\" src=\"https:\/\/platform.twitter.com\/embed\/Tweet.html?creatorScreenName=TechCrunch&amp;dnt=true&amp;embedId=twitter-widget-0&amp;features=eyJ0ZndfdGltZWxpbmVfbGlzdCI6eyJidWNrZXQiOlsibGlua3RyLmVlIiwidHIuZWUiLCJ0ZXJyYS5jb20uYnIiLCJ3d3cubGlua3RyLmVlIiwid3d3LnRyLmVlIiwid3d3LnRlcnJhLmNvbS5iciJdLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X2hvcml6b25fdGltZWxpbmVfMTIwMzQiOnsiYnVja2V0IjoidHJlYXRtZW50IiwidmVyc2lvbiI6bnVsbH0sInRmd190d2VldF9lZGl0X2JhY2tlbmQiOnsiYnVja2V0Ijoib24iLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X3JlZnNyY19zZXNzaW9uIjp7ImJ1Y2tldCI6Im9uIiwidmVyc2lvbiI6bnVsbH0sInRmd19jaGluX3BpbGxzXzE0NzQxIjp7ImJ1Y2tldCI6ImNvbG9yX2ljb25zIiwidmVyc2lvbiI6bnVsbH0sInRmd190d2VldF9yZXN1bHRfbWlncmF0aW9uXzEzOTc5Ijp7ImJ1Y2tldCI6InR3ZWV0X3Jlc3VsdCIsInZlcnNpb24iOm51bGx9LCJ0Zndfc2Vuc2l0aXZlX21lZGlhX2ludGVyc3RpdGlhbF8xMzk2MyI6eyJidWNrZXQiOiJpbnRlcnN0aXRpYWwiLCJ2ZXJzaW9uIjpudWxsfSwidGZ3X2V4cGVyaW1lbnRzX2Nvb2tpZV9leHBpcmF0aW9uIjp7ImJ1Y2tldCI6MTIwOTYwMCwidmVyc2lvbiI6bnVsbH0sInRmd19kdXBsaWNhdGVfc2NyaWJlc190b19zZXR0aW5ncyI6eyJidWNrZXQiOiJvbiIsInZlcnNpb24iOm51bGx9LCJ0ZndfdHdlZXRfZWRpdF9mcm9udGVuZCI6eyJidWNrZXQiOiJvZmYiLCJ2ZXJzaW9uIjpudWxsfX0%3D&amp;frame=false&amp;hideCard=false&amp;hideThread=false&amp;id=1570584747071639552&amp;lang=en&amp;origin=https%3A%2F%2Ftechcrunch.com%2F2022%2F09%2F15%2Fadobe-is-buying-figma-for-20b-taking-out-one-of-its-biggest-rivals-in-digital-design%2F&amp;sessionId=be5d5f434f2238050cdf90f4c325824b0187fe2b&amp;siteScreenName=TechCrunch&amp;theme=light&amp;widgetsVersion=1bfeb5c3714e8%3A1661975971032&amp;width=550px\" frameborder=\"0\" scrolling=\"no\" allowfullscreen=\"allowfullscreen\" data-tweet-id=\"1570584747071639552\" data-mce-fragment=\"1\"><\/iframe><\/div>\n<\/div>\n<p>According to Kevin Reed, CISO at cybersecurity company Acronis, the attacker found high-privileged credentials on a network file share and used them to access everything, including production systems, Uber\u2019s Slack management interface and the company\u2019s endpoint detection and response (EDR) portal.<\/p>\n<p>\u201cIf you had your data in Uber, there\u2019s a high chance so many people have access to it,\u201d Reed\u00a0<a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:6976395957387100160\/\" target=\"_blank\" rel=\"noopener\">said<\/a>\u00a0in a LinkedIn post, noting that it\u2019s not yet clear how the attacker bypassed two-factor authentication (<a href=\"https:\/\/techcrunch.com\/tag\/two-factor-authentication\/\">2FA<\/a>) after obtaining the employee\u2019s password.<\/p>\n<p>The attacker is also\u00a0<a href=\"https:\/\/twitter.com\/samwcyo\/status\/1570581007044317184\" target=\"_blank\" rel=\"noopener\">believed<\/a>\u00a0to have gained administrative access to Uber\u2019s cloud services, including on Amazon Web Services (AWS) and Google Cloud (GCP), where Uber stores its source code and customer data, as well as the company\u2019s\u00a0<a href=\"https:\/\/techcrunch.com\/tag\/hackerone\/\">HackerOne<\/a>\u00a0bug bounty program.<\/p>\n<p>Sam Curry, a security engineer at Yuga Labs who described the breach as a \u201ccomplete compromise,\u201d said that the threat actor likely had access to all of the company\u2019s vulnerability reports, which means they may have had access to vulnerabilities that have not been fixed. HackerOne has since disabled the Uber bug bounty program.<\/p>\n<p>In a statement given to TechCrunch, Chris Evans, HackerOne CISO and chief hacking officer, said the company \u201cis in close contact with Uber\u2019s security team, have locked their data down, and will continue to assist with their investigation.\u201d<\/p>\n<p>This is not the first time that Uber has been compromised. In 2016,\u00a0<a href=\"https:\/\/techcrunch.com\/2017\/11\/21\/uber-data-breach-from-2016-affected-57-million-riders-and-drivers\/\">hackers stole information from 57 million driver and rider accounts<\/a>\u00a0and then approached Uber and demanded $100,000 to delete the data. Uber made the payment to the hackers but kept the news of the breach quiet for more than a year.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>Posted from: <a href=\"https:\/\/tcrn.ch\/3UfM9pv\">https:\/\/tcrn.ch\/3UfM9pv<\/a><\/p>\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u00a0 \u00a0 Uber confirmed on Thursday that it\u2019s responding to a cybersecurity incident after reports claimed a hacker had breached its internal network. The ride-hailing giant discovered the breach on Thursday and has taken several of its internal communications and engineering systems offline while it investigates the incident, according to a\u00a0report by The New York&hellip;&nbsp;<a href=\"https:\/\/roglacup.com\/klaus62\/2022\/09\/18\/uber-investigating-cybersecurity-incident-after-hacker-breaches-its-internal-network-techcrunch\/\" class=\"\" rel=\"bookmark\">Read More &raquo;<span class=\"screen-reader-text\">Uber investigating cybersecurity incident after hacker breaches its internal network| TechCrunch<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":6230,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","footnotes":""},"categories":[384,29,4],"tags":[],"class_list":["post-6223","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-computer-science","category-economy-leadership","category-security"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/posts\/6223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/comments?post=6223"}],"version-history":[{"count":3,"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/posts\/6223\/revisions"}],"predecessor-version":[{"id":6232,"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/posts\/6223\/revisions\/6232"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/media\/6230"}],"wp:attachment":[{"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/media?parent=6223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/categories?post=6223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/roglacup.com\/klaus62\/wp-json\/wp\/v2\/tags?post=6223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}