{"id":460870,"date":"2022-09-16T10:36:03","date_gmt":"2022-09-16T08:36:03","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=460870"},"modified":"2022-09-16T10:43:11","modified_gmt":"2022-09-16T08:43:11","slug":"uber-hacked","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/460870-uber-hacked.html","title":{"rendered":"Uber hacked"},"content":{"rendered":"<p>Uber was the victim of a cyberattack on the afternoon of Thursday, 15 September 2022, with the culprit compromising its internal systems, email dashboard, and Slack server, Bleeping Computer <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/uber-hacked-internal-systems-breached-and-vulnerability-reports-stolen\/\" target=\"_blank\" rel=\"noopener\">reports<\/a><\/strong>.<\/p>\n<p>The attacker also accessed Uber vulnerability reports and shared screenshots which appear to prove that they had full access to various critical Uber IT systems.<\/p>\n<p>The compromised critical systems include Uber&#8217;s security software, Windows domain, Amazon Web Services console, email admin dashboard, and Slack server \u2014 to which the hacker posted messages.<\/p>\n<p>Uber <strong><a href=\"https:\/\/twitter.com\/Uber_Comms\/status\/1570584747071639552?s=20&amp;t=OM9eyfLwetZzFS9OEd_ptw\" target=\"_blank\" rel=\"noopener\">confirmed<\/a><\/strong> the attack on its Communications Twitter account.<\/p>\n<p>&#8220;We are currently responding to a cybersecurity incident. We are in touch with law enforcement and will post additional updates here as they become available,&#8221; it said.<\/p>\n<p>The New York Times <strong><a href=\"https:\/\/www.nytimes.com\/2022\/09\/15\/technology\/uber-hacking-breach.html\" target=\"_blank\" rel=\"noopener\">spoke to the malicious actor<\/a><\/strong>.<\/p>\n<p>They revealed that they gained access to Uber&#8217;s IT systems by performing a social engineering attack on an employee, through which they managed to steal the employee&#8217;s password.<\/p>\n<p>According to Yuga Labs security engineer <strong><a href=\"https:\/\/twitter.com\/samwcyo\/status\/1570577801790783493?s=20&amp;t=mgnS1nszWlkpCEkaZQB4Ag\" target=\"_blank\" rel=\"noopener\">Sam Curry<\/a><\/strong>, the attacker also managed to access the company&#8217;s HackerOne bug bounty programme and commented on all of Uber&#8217;s bug bounty tickets.<\/p>\n<p>&#8220;UBER HAS BEEN HACKED (domain admin, aws admin, vsphere admin, gsuite SA) AND THIS HACKERONE ACCOUNT HAS BEEN ALSO,&#8221; one of the comments reads.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/460748-serious-security-flaw-in-microsoft-teams.html\" rel=\"bookmark\">Serious security flaw in Microsoft Teams<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Uber says it&#8217;s &#8220;responding to a cybersecurity incident.&#8221;<\/p>\n","protected":false},"author":341076,"featured_media":421238,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[30594,81436,36922,81428,20853,807,81434],"class_list":["post-460870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-amazon-web-services","tag-sam-curry","tag-slack","tag-social-engineering-attack","tag-uber","tag-windows","tag-yuga-labs"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/460870"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=460870"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/460870\/revisions"}],"predecessor-version":[{"id":460874,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/460870\/revisions\/460874"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/421238"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=460870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=460870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=460870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}