← Uber

Lapsus$-affiliated hacker — full compromise (Slack, source, DBs)

2022 Unknown records affected Share on X

Data compromised

Source code, Employee data, Internal documents

Technical writeup

Hacker 'teapotuberhacker' announced breach in Uber Slack; source code, internal DBs, comms compromised. Social engineering—MFA bypass by spamming employee. Uber found no evidence of trip history access.

Root cause

Social engineering; MFA fatigue.

References