• Home
  • Afiliados
    • Programa Afiliados
    • Cadastrar Afiliado
    • Área Afiliados
  • Sair
  • Acesso Aluno
  • Home
  • Afiliados
    • Programa Afiliados
    • Cadastrar Afiliado
    • Área Afiliados
  • Sair
  • Acesso Aluno

Startup International

  • Home
  • Blog
  • Startup International

A teenager is reportedly behind Uber’s latest cybersecurity breach, gaining ‘full access’

  • Postado por Timwood Educacional
  • Categorias Startup International
  • Data 20/09/2022

[ad_1]

Uber on Friday confirmed it was investigating a “cyber security incident”, and that it had taken a number of its internal communications and engineering systems offline while this was taking place.

The company said it had also contacted law enforcement officials about the hack.

The hacker is understood to have gained access to Uber’s production systems, Slack management interface, its endpoint detection and response portal and its cloud services, which include the company’s source code and customer data.

Uber employees received a message from the hacker following the breach: “I announce I am a hacker and Uber has suffered a data breach.”

The New York Times interviewed the person who has claimed responsibility for the hack, who said they are just 18 years old.

The hacker said that they were able to gain access to the systems after sending a text message to an Uber worker claiming to be a corporate information tech person.

That worker was eventually persuaded to hand over a password that allowed the hacker to gain access to Uber’s system, they said.

They later added that they spammed the employee with push authentications for over an hour, then contacted them on WhatsApp claiming to be from Uber IT.

They told the employee that if he wants the messages to stop, he must accept the request. In doing this, the man added the hacker’s device, allowing them to gain access.

The apparent hacker told the New York Times they hacked into Uber because the company has “weak security”.

He also reportedly said that Uber drivers should be paid more.

Yuga Labs security engineer Sam Curry corresponded with the hacker and said they now “pretty much have full access to Uber”.

“This is a total compromise, from what it looks like,” Curry told the New York Times.

Acronis CISO Kevin Reed said the Uber breach is significant.

“Once on the internal network, the attackers found high privileged credentials laying on a network file share and used them to access everything, including production systems, corp EDR console, Uber slack management interface. This looks bad,” Reed posted on LinkedIn.

“What’s worse is if you had your data in Uber, there’s a high chance so many people have access to it. Say, if they know your email, they may then know where you live.”

Uber posted an update on the breach over the weekend.

“While our investigation and response efforts are ongoing, here is a further update on yesterday’s incident: we have no evidence that the incident involved access to sensitive user data (like trip history); all of our services…are operational; internal software tools that we took down as precaution yesterday are coming back online this morning,” Uber said in a statement.

Uber is a subscriber to HackerOne, a bug bounty platform which pays hackers to identify bugs in platforms and networks.

“We’re in close contact with Uber’s security team, have locked their data down, and will continue to assist with their investigation,” HackerOne chief hacking officer Chris Evans told the BBC.

It’s not the first time that Uber’s cyber security has been breached.

In 2016, hackers stole the names, email addresses and phone numbers of 50 million Uber users around the world, along with the driver’s licence numbers of 7 million drivers in the US. This included the personal information of 1.2 million Australians.

At the time, Uber paid a ransom to the hackers in an attempt to cover up the breach, which was not revealed for another year.

It wasn’t until July this year that the company officially owned up to the data breach, with Uber agreeing to pay a $212 million for civil litigation in relation to the incident.

As part of the settlement, Uber said that its staff “failed to report the November 2016 data breach”.



[ad_2]

  • Compartilhe:
Timwood Educacional

Post anterior

5 Key Steps to Health Insurance Benefits Renewal
20/09/2022

Próximo post

Rocket startup Gilmour Space is launching a 'caravan' into orbit in 2024
20/09/2022

Você também pode gostar

A Beginner’s Guide to Business Success in the Metaverse 
05/10/2022

[ad_1] Dr. Alex Young is an National Health Service (NHS)trauma and orthopedic surgeon, and CEO and founder at Virti. Passionate about improving human performance, he built and sold his first company while at university, before bootstrapping and scaling another while …

WiseTech Global donates $2.5 million to kids tech learning platform Grok Academy alongside 1% of profits pledge
04/10/2022

[ad_1] ASX-listed logistics company WiseTech Global has pledged 1% of its annual pre-tax profit to tech education through Grok Academy as part of a five-year deal. The deal, which kicks off with an FY22 contribution of more than $2.5 million, will …

The Australian Senate is holding an inquiry into the market dominance of Big Tech, including Meta, Google, Apple & Amazon
04/10/2022

[ad_1] The Senate Standing Committees on Economics’ Influence of International Digital Platforms inquiry has been tasked with exploring the degree to which major multinational technology companies – Meta, Google, Microsoft, Apple, Amazon and others are implied but not explicitly named – are …

Matricule-se Já!

  • Oferta! Basic Plan - Apenas Conteúdo
    Basic Plan – Apenas Conteúdo R$ 1.299,00 O preço original era: R$ 1.299,00.R$ 982,62O preço atual é: R$ 982,62. Adicionar ao carrinho

Posts recentes

  • How Important Is Learning English?
  • Dez Motivos para você aprender Inglês.
  • Como Me Mantenho Motivado Para Aprender Japonês? E Como Você Pode Fazer O Mesmo
  • Protegido: Relatório de Agendamento de Aulas
  • A Beginner’s Guide to Business Success in the Metaverse 
timwood-logo

Copyright © 2025, este site e todo seu conteúdo pertencem a TIMWOOD Educacional e possui seu direitos reservados.

  • Termos e Condições
  • Privacidade
  • Política de Cookies (BR)
  • Termos e Condições
  • Privacidade
  • Política de Cookies (BR)

Faça login com sua conta de site

Perdeu sua senha?