Uber has linked the cybersecurity incident it disclosed last week to hackers affiliated with the Lapsus$ gang, a group accused of numerous high-profile corporate data breaches.
The company also said the attackers were able to download or access company Slack messages and invoice-related data from an internal tool. on Monday, Uber said the attackers first gained access to the company's systems when they successfully convinced a contractor to grant a multi-factor authentication challenge. The contractor's network password had likely been obtained separately on a dark web marketplace, Uber said.
"From there, the attacker accessed several other employee accounts which ultimately gave the attacker elevated permissions to a number of tools, including G-Suite and Slack," the blog post said."The attacker then posted a message to a company-wide Slack channel, which many of you saw, and reconfigured Uber's OpenDNS to display a graphic image to employees on some internal sites.
The attacker did not access user-facing systems, user accounts, databases containing personal information or the code that powers Uber's products, the company said. But it added the investigation is continuing in coordination with law enforcement and multiple cybersecurity firms. The blog post marks the first time Uber has publicly attributed the incident to the Lapsus$ gang, which targeted Microsoft earlier this year and is also accused of attacking Nvidia, Okta and other companies.
Uber added that in response to the breach, it is strengthening its multifactor authentication policies and has reset employee access to internal tools.
Canada Latest News, Canada Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
Uber claims hack came from Lapsus$, the group behind Microsoft and T-Mobile attacks | EngadgetUber says a recent hack that breached its systems was the work of Lapsus$, which also targeted Microsoft..
Read more »
Uber blames Lapsus$ hacking group for security breachUber reiterates that personal data remains safe.
Read more »
Any one of these 15 money-losing companies could become the stock market's biggest 'unicorn' failure everOPINION: The 15 biggest money-losing companies in the U.S. have cumulatively raised $93.8 billion in funds and lost $135.1 billion. A failure of these two would be 10 times larger than the previous records for lost venture-capital funding.
Read more »
Report: Uber Hacked by Teenager, Employees Thought It Was a JokeRidesharing giant Uber says that is investigating a 'cybersecurity incident' after a hacker claiming to be just 18 years old stated that they have administrator access to company tools.
Read more »
Uber Hacker Claims To Have Hacked Rockstar Games, Releases GTA 6 VideosDid the hacker behind the Uber hack just breach Rockstar Games' servers and leak Grand Theft Auto 6 development videos?
Read more »
Uber now offers EV rides in 25 citiesUber has expanded its Comfort Electric service 'nationwide to 24 U.S. cities, letting users request rides in all-electric vehicles.
Read more »