The Uber hacks, start to finish: a bought password, a tired yes and a security chief's conviction
In September 2022 an intruder got into Uber with a password bought from criminals and a single tap on a contractor's phone, and 3 weeks later a federal jury convicted Uber's former security chief over how the company had handled a different breach 6 years earlier.[1][5] This long read covers both: the login, the keys left in a script, Uber's own account, the 2016 payoff, the verdict, and the one control that ties them together.
The bought password and the approval prompt
The way in did not start with an Uber employee. It started with an outside contractor. According to Uber's own account, filed with the Securities and Exchange Commission, the contractor's personal device had been infected with malware that exposed their Uber login, and the attacker most likely bought that corporate password on the dark web.[1]
A password alone should not have been enough. Uber's sign-in also asked for a second step: an approval request sent to the contractor's phone. The attacker tried to log in repeatedly, and each request was refused. Then, Uber said, the contractor accepted one, and the attacker was in.[1]
The attacker gave his own version to researchers while the breach was still unfolding. He said he sent approval prompts for more than an hour, then contacted the contractor on a messaging app while posing as a member of Uber's IT team and suggested that accepting the prompt would make the notifications stop.[2] Uber did not confirm that part, but its timeline of repeated refusals followed by one approval matches it.[1]
Security people call this approval fatigue: flood someone with prompts at an awkward hour, add a plausible voice claiming to be the help desk, and wait for a tired person to press yes. It works because a push prompt asks a human to judge a login they did not start, with no easy way to see who is really behind it. Sign-in methods tied to a physical key or to the specific website do not have that weakness, because there is nothing for the user to approve on someone else's behalf.
The admin password left in a script
A contractor's account is a small key. What turned it into a large one, according to what the attacker told researchers, was a script he found on a shared internal network drive. The script contained, in plain text, the login for an administrator account on the system Uber used to store and hand out its other privileged passwords.[2] Uber has not publicly confirmed that detail.
From there, the attacker claimed access to email, cloud systems and source code, and screenshots he shared led one well-known security researcher to say he appeared to have near-total access.[2] Uber's own list of what was touched was shorter but still serious: several employee accounts with elevated permissions, the company's email and document suite, its Slack workspace, from which some messages were downloaded, a finance tool used for invoices, and Uber's dashboard on the bug bounty platform where outside researchers report security flaws.[1]
The attacker also announced himself. On the evening of September 15, 2022, he posted to a company-wide Slack channel that he was a hacker and that Uber had suffered a data breach. Some employees reportedly took it for a joke at first.[3] Uber took Slack and other internal tools offline while it investigated.[1][3]
What Uber said the intruder took
On September 19, 2022, Uber published an update. It said the attacker was likely affiliated with a group that had breached Microsoft, Cisco, Samsung, Nvidia and Okta earlier that year, and that it was working with the FBI and the Justice Department.[1]
Uber also said it had found no evidence that the attacker reached the production systems that run its apps, user accounts or the databases holding sensitive customer information such as card numbers, bank details or trip histories. It said no changes had been made to its code, and that its services stayed up throughout.[1]
The response steps it listed read like a checklist for this kind of intrusion: block or reset compromised accounts, disable affected internal tools, rotate keys, lock the code from changes, force everyone to sign in again, and tighten multifactor sign-in rules.[1] In the attacker's own telling, he was 18 and had done it to show that Uber's security was weak.[2] In the UK, a jury later found that a teenager who was 17 at the time had carried out the Uber intrusion along with other attacks linked to the same group. Because he was found unfit to stand trial, the jury decided whether he had done the acts rather than returning a criminal conviction.[11]
The 2016 breach Uber hid
The timing was awkward for a reason. That same month, Uber's handling of an older breach was on trial in San Francisco.
In 2016, hackers got into Uber's cloud storage and took data on about 57 million riders and drivers, including the names and license numbers of about 600,000 drivers.[4] They contacted Uber to demand payment. The company was already under investigation by the Federal Trade Commission over an earlier breach from 2014, and its chief security officer, Joe Sullivan, had testified to the agency about Uber's security in November 2016. About 10 days later, he learned of the new breach.[5] Prosecutors said he told a subordinate it would play very badly given what Uber had already told the FTC.[5]
Instead of reporting it, Uber paid the hackers $100,000 through its bug bounty program, which is meant to reward researchers who find and report flaws and normally had a cap of $10,000. The hackers signed nondisclosure agreements that falsely said they had not taken or kept any data.[4] The breach stayed hidden until a new chief executive disclosed it in November 2017, a year after it happened.[4][5] In September 2018, Uber paid $148 million to settle with all 50 states and the District of Columbia.[6]
The verdict against Uber's former security chief
In August 2020, federal prosecutors charged Joe Sullivan with obstruction of justice and concealing a felony.[4] In July 2022, Uber itself entered a non-prosecution agreement with the Justice Department in which it admitted that its staff had concealed the 2016 breach from the FTC, and agreed to cooperate in the case.[7]
Sullivan's trial ran in September 2022, in the same weeks the new intruder was inside Uber's network. In October 2022 the jury found him guilty on both counts.[5][8] It was widely described as the first criminal conviction of a corporate security executive over how a breach was handled.[8] On May 4, 2023, a federal judge sentenced him to 3 years of probation and a $50,000 fine.[5][9]
Sullivan appealed. In March 2025 the Ninth Circuit Court of Appeals upheld the conviction.[10] The case changed how security leaders talk about breach disclosure: the cover-up, not the hack, is what ended in a criminal record.
One thread through two breaches
Lay the 2 incidents side by side and they fail in different places but the same way. In 2022, the defense rested on a prompt that a worn-down person could approve and on a powerful password sitting in a file anyone inside could read.[1][2] In 2016, it rested on a few people deciding that silence was safer than disclosure.[5]
In each case, one human decision was the only thing standing between an attacker and serious damage, and nothing in the system checked that decision. Good security design assumes people will be tired, rushed or under pressure, and removes the single points where one yes, or one quiet payment, can undo everything else.
Timeline
| Date | What happened |
|---|---|
| Nov 2016 | Security chief testifies to the FTC; about 10 days later learns of a new breach.[5] |
| Late 2016 | Uber pays hackers $100,000 through its bug bounty program.[4] |
| Nov 2017 | New CEO discloses the 2016 breach of about 57 million records.[4] |
| Sep 2018 | Uber settles with all 50 states and D.C. for $148 million.[6] |
| Aug 2020 | Former security chief charged.[4] |
| Jul 2022 | Uber signs a non-prosecution agreement admitting the cover-up.[7] |
| Sep 15, 2022 | Intruder posts in Uber's company-wide Slack.[3] |
| Sep 19, 2022 | Uber publishes its account of the intrusion.[1] |
| Oct 2022 | Jury convicts the former security chief on both counts.[8] |
| May 4, 2023 | Sentenced to 3 years of probation and a $50,000 fine.[9] |
| Mar 2025 | Ninth Circuit upholds the conviction.[10] |
The missing control
The missing control: use sign-in methods that cannot be approved by a tired thumb, keep privileged passwords out of scripts and shared files, and have a breach process that reports instead of pays for silence. The first 2 would have kept the 2022 intruder small; the third would have kept 2016 from becoming a criminal case.[1][5]
- Replace push-to-approve with stronger sign-in. Where your email and cloud tools allow it, use security keys or passkeys for staff and contractors, or at least number-matching prompts that require typing a code shown on screen.
- Tell staff the help desk never asks for approvals. Make it a written rule that nobody from IT will ever ask them to accept a login prompt, and that unexpected prompts get reported, not accepted.
- Search shared drives for stored passwords. Look for scripts, spreadsheets and documents containing logins, move them into a password manager, and change every password you find.
- Give contractors the least access that works. Separate contractor accounts from admin rights and review each one quarterly; remove any that are no longer needed.
- Write down who decides on disclosure. Before anything happens, name the people who assess a breach, involve a lawyer, and set the rule that extortion demands are reported, never quietly paid off.
What it means now
The 2022 intrusion cost a bought password and some persistence. The 2016 cover-up cost $148 million in settlements and a felony conviction. Both are reminders that the expensive failures are usually decisions, not technology.
For a small business, the lesson fits on an index card: make sure one tired yes cannot open everything, keep your master keys out of files, and decide in advance that you will report a breach rather than hope nobody finds out.
How Uber got hacked in 2022: a stolen password and one tired tap: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Uber (SEC Form 8-K exhibit): Security update, September 2022
- Dark Reading: Hacker pwns Uber via compromised VPN account
- CNBC: Uber investigates cybersecurity incident after reports of a hack
- NPR: Former Uber executive charged with paying hush money to conceal massive breach
- U.S. Attorney's Office, N.D. California: Former chief security officer of Uber sentenced to three years' probation for covering up data breach
- Hunton Andrews Kurth: Uber settles with 50 state attorneys general for $148 million in connection with 2016 data breach
- U.S. Attorney's Office, N.D. California: Uber enters non-prosecution agreement
- Norton Rose Fulbright: US jury convicts former chief security officer for mishandling cybersecurity breach
- The Record: Former Uber CISO avoids prison, sentenced to three-year probation
- The Record: Appellate court upholds sentence for former Uber cyber executive Joe Sullivan
- BusinessDay (Reuters): London court finds teen hacked Uber and Revolut