• Loading ...
  • Loading ...

Accommodation New Zealand

Uber responding to ‘cybersecurity incident’ after hack

17 Sep 2022 By theguardian

Uber responding to ‘cybersecurity incident’ after hack

Accommodation New Zealand introduces

Uber has been hacked in an attack that appears to have breached the ride-hailing company's internal systems.

The California-based company confirmed it was responding to a "cybersecurity incident", after the New York Times reported that a hack had accessed the company's network and forced it to take several internal communications and engineering systems offline. The hacker claimed to be 18 years old, according to the report.

Uber confirmed that there are no issues with the company's service, which operates in more than 10,000 cities around the world.

A hacker compromised the employee workplace messaging app Slack and used it to send a message to Uber employees announcing that it had suffered a data breach.

Sam Curry, a senior engineer at non-fungible token creator Yuga Labs, said he was contacted by the Uber hacker on the HackerOne platform and had been shown "very convincing" screenshots of full administrative access to Uber's cloud services.

"From my understanding, the attacker had keys to the kingdom after obtaining an internal file with credentials to nearly everything," Curry told the Guardian. He added: "Based on the screenshots and my understanding of the hack, they likely had access to read/modify the cloud services which run Uber and store user information."

The company has been hacked before. Its former chief security officer, Joseph Sullivan, is on trial on allegations he arranged to pay hackers $100,000 as part of an attempt to cover up a 2016 attack in which the personal information of about 57 million customers and drivers was stolen.

Alan Woodward, a professor of cybersecurity at Surrey University, said: "As the hacker does appear to have such high-level access it's also going to be difficult for Uber to know they have managed to remove the hacker from the network. It could mean a major rebuild of their systems, which will cause serious disruption."

It appeared the hacker was able to gain access to other internal company systems, posting an explicit photo on an internal information page for employees, according to the New York Times. "We are in touch with law enforcement and will post additional updates here as they become available," Uber said in the tweet confirming the attack.

The Slack system was taken offline on Thursday afternoon by Uber after employees received the message from the hacker.

"I announce I am a hacker and Uber has suffered a data breach," the message read, going on to list several internal databases that were claimed to be compromised, the report added.

The New York Times reported that the person who claimed responsibility for the hack said they gained access through social engineering, a term for tricking an employee into granting access.

The hacker sent a text message to an Uber worker claiming to be a company tech employee and persuaded the worker to hand over a password that gave them access to the network. The hacker, who had provided a Telegram account address, said they broke in because the company had weak security, according to the report.

Staff at the company were instructed to not use Slack. Other internal systems, too, were reportedly inaccessible.

Are you looking for a holiday? Get special deals.

 

More News

Booking.com
US targets Chinese robots over security fears
US targets Chinese robots over security fears
SSA impersonation scams are getting more personal
SSA impersonation scams are getting more personal
Hidden NYC tunnel tied to Underground Railroad at risk of 'significant damage,' advocates warn
Hidden NYC tunnel tied to Underground Railroad at risk of 'significant damage,' advocates warn
Coin used as bus fare turns out to be 2,000-year-old relic, its journey still a mystery
Coin used as bus fare turns out to be 2,000-year-old relic, its journey still a mystery
Cruise lines cancel sailings, reroute ships as Middle East conflict disrupts voyages
Cruise lines cancel sailings, reroute ships as Middle East conflict disrupts voyages
World's oldest known land animal alive after viral death hoax fools thousands
World's oldest known land animal alive after viral death hoax fools thousands
Ricky Saints hopes to add to his accolades with NXT Championship victory at Stand & Deliver
Ricky Saints hopes to add to his accolades with NXT Championship victory at Stand & Deliver
Stephen A Smith, former ESPN colleague clash about why men stay silent on trans athletes in girls' sports
Stephen A Smith, former ESPN colleague clash about why men stay silent on trans athletes in girls' sports
Airline cracks down on crew's weight, fitness and health, warning some staff could be pulled from flights
Airline cracks down on crew's weight, fitness and health, warning some staff could be pulled from flights
Artemis II launch steals the show at college softball game as players stare skyward in amazement
Artemis II launch steals the show at college softball game as players stare skyward in amazement
Migrant charged in Gilgo Beach throat slashing, fueling serial killer copycat fears
Migrant charged in Gilgo Beach throat slashing, fueling serial killer copycat fears
'Boy Meets World' star Danielle Fishel admits body-shaming nearly ended her on-camera career
'Boy Meets World' star Danielle Fishel admits body-shaming nearly ended her on-camera career
Trevor Bauer signs with pro baseball team in United States amid MLB return hopes
Trevor Bauer signs with pro baseball team in United States amid MLB return hopes
Leslie Jones declares 'marriage is legalized slavery,' may as well involve 'whip and chain'
Leslie Jones declares 'marriage is legalized slavery,' may as well involve 'whip and chain'
American Airlines flight diverted to Detroit after passenger allegedly makes ominous threat
American Airlines flight diverted to Detroit after passenger allegedly makes ominous threat
KitKat launches stolen chocolate tracker after thieves plunder 12 tons: Check your candy
KitKat launches stolen chocolate tracker after thieves plunder 12 tons: Check your candy
Meryl Streep claims SAVE America Act forces married women to 'prove who they are' to vote
Meryl Streep claims SAVE America Act forces married women to 'prove who they are' to vote
Fatal drug combination sparks alert as 'rhino tranq' spreads across US
Fatal drug combination sparks alert as 'rhino tranq' spreads across US
MLB's top prospect Konnor Griffin set to make major league debut at just 19 years old
MLB's top prospect Konnor Griffin set to make major league debut at just 19 years old
Man accused of killing parents with hammer, knife, then calling 911 to confess: report
Man accused of killing parents with hammer, knife, then calling 911 to confess: report