Hacker claims to breach Uber, security researcher says

Sep 15, 2022, 8:17 PM | Updated: 9:27 pm

Uber said Thursday that it reached out to law enforcement after a hacker apparently breached its network. A security engineer said the intruder had provided evidence of obtaining access to crucial cloud systems at the ride-hailing service.

There was no indication that Uber’s fleet of vehicles or its operation was in any way affected.

“It seems like they’ve compromised a lot of stuff,” said Sam Curry, an engineer with Yuga Labs who communicated with the hacker. That includes obtaining complete access to the Amazon and Google-hosted cloud environments where Uber stores its source code and customer data, he said.

Curry said he spoke to several Uber employees who said they were “working to lock down everything internally” to restrict the hacker’s access. That included the company’s Slack internal messaging network, he said.

He said there was no indication that the hacker had done any damage or was interested in anything more than publicity. “My gut feeling is that it seems like they are out to get as much attention as possible.”

The hacker had alerted Curry and other security researchers to the intrusion by using and an internal Uber account to comment on vulnerabilities they had previously identified on the company’s network through its bug-bounty program, which pays ethical hackers to identify vulnerabilities.

The hacker provided a Telegram account address and Curry and other researchers then engaged them in a separate conversation, sharing screenshots of various pages from Uber’s cloud providers to prove they broke in.

The Associated Press attempted to contact the hacker at the Telegram account where Curry and the other researchers chatted with them. But no one responded.

One screenshot posted on Twitter and confirmed by researchers shows a chat with the hacker in which they say they obtained the credentials of an administrative user and then used social engineering to access Uber’s internal network.

Uber said via email that it was “currently responding to a cybersecurity incident. We are in touch with law enforcement.” It said it would provide updates on its Uber Comms twitter feed.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Haitian migrant Gerson Solay, 28, carries his daughter, Bianca, as he and his family cross into Can...
Associated Press

US, Canada to end loophole that allows asylum-seekers to move between countries

President Joe Biden and Canadian Prime Minister Justin Trudeau on Friday announced a plan to close a loophole to an immigration agreement.
2 days ago
Expert skateboarder Di'Orr Greenwood, an artist born and raised in the Navajo Nation in Arizona and...
Associated Press

Indigenous skateboard art featured on new stamps unveiled at Phoenix skate park

The Postal Service unveiled the “Art of the Skateboard" stamps at a Phoenix skate park, featuring designs from Indigenous artists.
2 days ago
(Facebook Photo/City of San Luis, Arizona)...
Associated Press

San Luis authorities receive complaints about 911 calls going across border

Authorities in San Luis say they are receiving more complaints about 911 calls mistakenly going across the border.
8 days ago
(Pexels Photo)...
Associated Press

Daylight saving time begins in most of US this weekend

No time change is observed in Hawaii, most of Arizona, Puerto Rico, the U.S. Virgin Islands, American Samoa, Guam and the Northern Marianas.
16 days ago
Mexican army soldiers prepare a search mission for four U.S. citizens kidnapped by gunmen in Matamo...
Associated Press

How the 4 abducted Americans in Mexico were located

The anonymous tip that led Mexican authorities to a remote shack where four abducted Americans were held described armed men and blindfolds.
16 days ago
Tom Brundy points to a newly built irrigation canal on one of the fields at his farm Tuesday, Feb. ...
Associated Press

Southwest farmers reluctant to idle farmland to save water

There is a growing sense that fallowing will have to be part of the solution to the increasingly desperate drought in the West.
23 days ago

Sponsored Articles

...
Day & Night Air Conditioning, Heating and Plumbing

Company looking for oldest air conditioner and wants to reward homeowner with new one

Does your air conditioner make weird noises or a burning smell when it starts? If so, you may be due for an AC unit replacement.
...
Quantum Fiber

How high-speed fiber internet edges out cable for everyday use

In a world where technology drives so much of our daily lives, a lack of high-speed internet can be a major issue.
...
Day & Night Air Conditioning, Heating and Plumbing

Prep the plumbing in your home just in time for the holidays

With the holidays approaching, it's important to know when your home is in need of heating and plumbing updates before more guests start to come around.
Hacker claims to breach Uber, security researcher says