Hacker claims to breach Uber, security researcher says

Sep 15, 2022, 8:17 AM | Updated: 9:16 pm

Uber said Thursday that it reached out to law enforcement after a hacker apparently breached its network. A security engineer said the intruder had provided evidence of obtaining access to crucial cloud systems at the ride-hailing service.

There was no indication that Uber’s fleet of vehicles or its operation was in any way affected.

“It seems like they’ve compromised a lot of stuff,” said Sam Curry, an engineer with Yuga Labs who communicated with the hacker. That includes obtaining complete access to the Amazon and Google-hosted cloud environments where Uber stores its source code and customer data, he said.

Curry said he spoke to several Uber employees who said they were “working to lock down everything internally” to restrict the hacker’s access. That included the company’s Slack internal messaging network, he said.

He said there was no indication that the hacker had done any damage or was interested in anything more than publicity. “My gut feeling is that it seems like they are out to get as much attention as possible.”

The hacker had alerted Curry and other security researchers to the intrusion by using and an internal Uber account to comment on vulnerabilities they had previously identified on the company’s network through its bug-bounty program, which pays ethical hackers to identify vulnerabilities.

The hacker provided a Telegram account address and Curry and other researchers then engaged them in a separate conversation, sharing screenshots of various pages from Uber’s cloud providers to prove they broke in.

The Associated Press attempted to contact the hacker at the Telegram account where Curry and the other researchers chatted with them. But no one responded.

One screenshot posted on Twitter and confirmed by researchers shows a chat with the hacker in which they say they obtained the credentials of an administrative user and then used social engineering to access Uber’s internal network.

Uber said via email that it was “currently responding to a cybersecurity incident. We are in touch with law enforcement.” It said it would provide updates on its Uber Comms twitter feed.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

FILE - The draft of a bill that President Joe Biden and House Speaker Kevin McCarthy of Calif., neg...

Associated Press

Debt deal imposes new work requirements for food aid and that frustrates many Democrats

Democrats are deeply conflicted about the debt ceiling deal, fearing damage has been done to safety net programs

23 hours ago

Seattle lawyer...

Associated Press

Lawsuit alleging ex-deputy falsified arrest report settled for $250K

A lawsuit filed by a Washington oyster farmer accusing a former county deputy of falsifying an arrest report

23 hours ago

biden crisis averted...

Zeke Miller and Chris Megerian

Biden celebrates a ‘crisis averted’ in Oval Office address on bipartisan debt ceiling deal

President Joe Biden celebrated a “crisis averted” in his first speech to the nation from the Oval Office Friday evening.

3 days ago

Margrethe Vestager, Executive Vice-President for A Europe Fit for the Digital Age and Competition, ...

Associated Press

US, Europe working on voluntary AI code of conduct as calls grow for regulation

The United States and Europe are drawing up a voluntary code of conduct for artificial intelligence as the developing technology triggers warnings

3 days ago

FILE - Idaho Attorney General candidate Rep. Raul Labrador speaks during the Idaho Republican Party...

Associated Press

Families sue to block Idaho law barring gender-affirming care for minors

The families of two transgender teenagers filed a lawsuit Thursday to block enforcement of Idaho's ban on gender-affirming medical care for minors.

4 days ago

Amazon agreed Wednesday to pay a $25 million civil penalty to settle Federal Trade Commission alleg...

Associated Press

Amazon fined $25M for violating child privacy with Alexa

Amazon agreed Wednesday to pay a $25 million civil penalty to settle Federal Trade Commission allegations it violated a child privacy law

4 days ago

Sponsored Articles

Men's Health Month...

Men’s Health Month: Why It’s Important to Speak About Your Health

June is Men’s Health Month, with the goal to raise awareness about men’s health and to encourage men to speak about their health.

Internet Washington...

Major Internet Upgrade and Expansion Planned This Year in Washington State

Comcast is investing $280 million this year to offer multi-gigabit Internet speeds to more than four million locations.

Compassion International...

Brock Huard and Friends Rally Around The Fight for First Campaign

Professional athletes are teaming up to prevent infant mortality and empower women at risk in communities facing severe poverty.

Emergency Preparedness...

Prepare for the next disaster at the Emergency Preparedness Conference

Being prepared before the next emergency arrives is key to preserving businesses and organizations of many kinds.

SHIBA volunteer...

Volunteer to help people understand their Medicare options!

If you’re retired or getting ready to retire and looking for new ways to stay active, becoming a SHIBA volunteer could be for you!

safety from crime...

As crime increases, our safety measures must too

It's easy to be accused of fearmongering regarding crime, but Seattle residents might have good reason to be concerned for their safety.

Hacker claims to breach Uber, security researcher says