Skip to content

2022-09-15 (incident) · US · Uber

Uber contractor account breached through repeated MFA prompts, 2022

Disclosed by the affected organisation.

In September 2022 an attacker who likely bought an Uber contractor's corporate password on the dark web tried to log in again and again, triggering two-factor approval requests, until the contractor accepted one. Uber said the attacker then reached other employee accounts, gained elevated permissions to tools including G-Suite and Slack, and downloaded some internal Slack messages and information from an internal finance tool used to manage some invoices. Uber linked the attacker to the Lapsus$ group.

Timeline

  1. 2022-09-15 Uber posts its first notice about a cybersecurity incident.
  2. 2022-09-16 Uber says all its services are operational.
  3. 2022-09-19 Uber publishes its investigation update: a contractor accepted one of repeated two-factor login approval requests.

Lessons

Scam types: MFA fatigue (push bombing)

Sources

  1. Uber: Security update (September 2022) (Company disclosure, primary, accessed 2026-09-24)