Toutes les vulnérabilités
HIGHOpSec

OPSEC-UBER-2022

Identity · Uber

Résumé

In September 2022, an external contractor's Uber corporate credentials were compromised, likely purchased on the dark web after malware infected the contractor's personal device. The attacker launched an MFA fatigue push-bombing attack, flooding the contractor with 2FA approval requests, then posed as Uber IT over WhatsApp to convince them to approve one. Once inside, lateral movement reached hardcoded admin credentials in a PowerShell script on a network share, granting elevated access to G-Suite, Slack, vSphere, internal dashboards, and the HackerOne environment. Uber attributed the intrusion to an actor affiliated with Lapsus$ and stated no sensitive user data was exfiltrated.

Références

Vulnérabilités liées

Tout OpSec →