How Uber got hacked in 2022: a stolen password and one tired tap
Uber's September 2022 breach did not start with a clever exploit. It started when a contractor, after rejecting a string of login approval prompts on their phone, finally accepted one.[1] This case file covers how a stolen password and a worn-down approval habit opened Uber's internal tools, how it was caught, and the one control that would have stopped it.
What happened
On September 15, 2022, an intruder logged in to Uber's systems using the account of an external contractor.[1][2] Uber later said the contractor's personal device had likely been infected with malware, and that the password had probably been bought on the dark web, the criminal marketplaces where stolen logins are sold.[1]
The password alone was not enough. Every sign-in attempt sent an approval request to the contractor's phone, and Uber said the contractor rejected those requests at first. The attacker kept trying, and eventually the contractor accepted one.[1] The person who claimed responsibility told reporters they had texted an Uber worker while posing as corporate IT to get the access.[3]
Once in, the intruder reached several employee accounts with elevated permissions, along with Google Workspace and Slack. They posted a message to a company-wide Slack channel, changed an internal web setting so staff pages showed a graphic image, and got into Uber's bug bounty dashboard, where outside researchers report security flaws.[1][2] Employees were told to stop using Slack, and Uber took some internal systems offline while it investigated.[3]
How they got in
This attack is often called push fatigue or approval fatigue. Many companies use multi-factor authentication (MFA), a second check after the password, in its simplest form: a pop-up on your phone asking whether to allow a login. That works when the pop-up is rare. When an attacker already holds the password, they can trigger the prompt again and again, often at odd hours, until the person gives in or is persuaded that approving it is routine.[1][2]
The phone prompt did its job for a while, which is the point. It turned the decision into a human judgment call made under pressure, and a message claiming to come from the help desk was enough to tip it.[3]
The first login was also not the end of the damage. Security researchers reviewing the intruder's claims reported that, once inside, the attacker found an unprotected network folder containing scripts with administrator credentials written directly into them, which opened far more of the company.[4] One weak doorway led to a hallway full of keys.
How it was caught
Uber did not have to find the intruder. The intruder announced themselves, posting to company Slack and to the bug bounty system that the company had been hacked.[3][4] Uber said it responded by locking down affected accounts, resetting access, rotating keys, freezing changes to its code, tightening its MFA policies and adding monitoring, and it notified law enforcement.[1]
Uber attributed the attack to Lapsus$, a group that also hit Microsoft, Cisco, Samsung, Nvidia and Okta in 2022.[1][2] The person who claimed the hack said they were 18.[3][4]
In the UK, police arrested a teenager in September 2022 after he kept attacking companies while on bail. In August 2023 a London jury found that he had hacked Uber and the fintech firm Revolut and blackmailed a video game company. He had been ruled unfit to stand trial, so the jury decided whether he did the acts rather than returning a guilty verdict.[6] In December 2023 he was given an indefinite hospital order, and a second, younger member of the group received an 18-month youth rehabilitation order.[5]
What it cost
Uber said it found no evidence that the intruder reached its production systems, rider or driver accounts, card or bank details, trip history, or its cloud storage, and no unauthorized code changes.[1] The intruder did download internal Slack messages and information from a finance tool used to manage some invoices.[1][2] Uber did not publish a dollar figure for the response. The real cost was days of disruption and a very public lesson for every company still relying on simple phone prompts.
The missing control
The missing control: phishing-resistant MFA instead of push approvals. That means a second factor tied to the real website and device, such as a hardware security key or a passkey, that cannot be approved from a pop-up or talked out of a tired user.
With a key or passkey, a stolen password plus a phone call gets an attacker nothing, because there is no prompt to accept and the login only works on the real site with the physical key present. Even a step short of that, such as number matching, where the user must type a code shown on the login screen, and a limit on repeated prompts, would have made a blind approval far harder. Removing hard-coded admin credentials would have shortened what came next.[4]
What to do in your business
- Turn off simple approve-or-deny prompts. In your email and cloud accounts, switch MFA to number matching now, and plan a move to security keys or passkeys for admins and anyone who handles money.
- Tell staff that unexpected prompts are an alarm. Make a simple rule: if you did not just try to log in, deny it and report it, even if someone calls saying they are IT.
- Verify help desk contacts. Real IT will never ask you to approve a prompt or read out a code. Give staff one known number to call back.
- Hold contractors to the same standard. Contractors and their personal devices can be the way in. Require the same MFA and cut access the day work ends.
- Search for passwords stored in files. Ask your IT provider to look for admin logins saved in scripts, shared folders or spreadsheets, and move them into a password manager.
The Uber hacks, start to finish: a bought password, a tired yes and a security chief's conviction: the long read behind the CL13 episode, chapter by chapter.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How the MGM Resorts cyberattack happened: the help desk call that cost $100 million
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Uber (SEC Form 8-K exhibit): Security update
- Help Net Security: Uber says Lapsus$ gang is behind the recent breach
- Boston.com: Uber investigating breach of its computer systems
- Sophos: Uber has been hacked, boasts hacker - how to stop it happening to you
- The Hacker News: British LAPSUS$ teen members sentenced
- BusinessDay (Reuters): London court finds teen hacked Uber and Revolut