Uber Suffers Major Cybersecurity Breach Through MFA Exploitation

An 18-year-old hacker breaches Uber's internal systems by tricking an employee into approving a multi-factor authentication request. The company confirms no sensitive customer trip or financial data is stolen during the incident.

Uber confirms that its services operate normally following a significant cybersecurity incident that allows a hacker to access internal systems containing vast amounts of customer data. The attacker, who claims to be an 18-year-old affiliated with the Lapsus$ group, posts screenshots on Twitter showing compromised internal dashboards, Slack workspaces, and HackerOne accounts. Although the hacker successfully steals internal information and Slack messages, Uber states that sensitive user data, such as credit card numbers and trip histories, remains secure.

The breach originates from a targeted social engineering attack where the hacker obtains an Uber contractor's password and bombards the employee with multi-factor authentication (MFA) push notifications. Eventually, the contractor approves one of these fraudulent requests, giving the attacker the critical foothold needed to enter the network. From there, the hacker discovers a network share containing high-privilege credentials, which grants near-unfettered access to the rest of Uber's corporate infrastructure.

Security experts highlight that this incident exposes a growing vulnerability in MFA protections that rely on human behavior rather than technical interception. While modern push notifications and authenticator apps replace older, easily intercepted text message codes, attackers now simply overwhelm users with login prompts until they accidentally grant access. As Uber conducts its post-mortem investigation, the tech industry focuses on how even the world's largest companies struggle to defend against these sophisticated psychological tactics.

Read More at the original source →