2022-09-15 (incident) · US · Uber
Uber contractor account breached through repeated MFA prompts, 2022
Disclosed by the affected organisation.
In September 2022 an attacker who likely bought an Uber contractor's corporate password on the dark web tried to log in again and again, triggering two-factor approval requests, until the contractor accepted one. Uber said the attacker then reached other employee accounts, gained elevated permissions to tools including G-Suite and Slack, and downloaded some internal Slack messages and information from an internal finance tool used to manage some invoices. Uber linked the attacker to the Lapsus$ group.
Timeline
- 2022-09-15 Uber posts its first notice about a cybersecurity incident.
- 2022-09-16 Uber says all its services are operational.
- 2022-09-19 Uber publishes its investigation update: a contractor accepted one of repeated two-factor login approval requests.
Lessons
- Replace simple push approvals with number matching or phishing-resistant MFA so a flood of prompts cannot be approved by accident.
- Alert on repeated failed MFA prompts for one account and treat an approval after a flood as a likely compromise.
- Hold contractors to the same device security and MFA standards as employees, since malware on a contractor device exposed this password.
Scam types: MFA fatigue (push bombing)
Sources
- Uber: Security update (September 2022) (Company disclosure, primary, accessed 2026-09-24)