Uber deals with 'cybersecurity incident' after hacker appears to breach its system

Uber said on Thursday it had contacted police after a hacker apparently breached its network. A security engineer said the intruder prov...


Uber said on Thursday it had contacted police after a hacker apparently breached its network. A security engineer said the intruder provided evidence of gaining access to crucial cloud systems in the ride-sharing service.

Uber tweeted Thursday night that it was “currently responding to a cybersecurity incident. We are in contact with law enforcement.”

He said he would provide updates on his Uber communications Twitter feed. When contacted by CBS News, an Uber spokesperson declined to provide details.

There was no indication that Uber’s vehicle fleet or its operation was affected in any way.

“It looks like they compromised a lot,” said Sam Curry, an engineer at Yuga Labs who communicated with the hacker. This includes gaining full access to the cloud environments hosted by Amazon and Google, where Uber stores its source code and customer data, he said.

Curry said he spoke to several Uber employees who said they were “working to lock down everything internally” to restrict the hacker’s access. That included the company’s internal Slack messaging network, he said.

He said there was no indication that the hacker had done any harm or was interested in anything more than publicity. “My hunch is that it looks like they want to get as much attention as possible.”

The hacker alerted Curry and other security researchers to the hack using an internal Uber account to comment on vulnerabilities they had previously identified on the company’s network through its bug bounty program, which pays ethical hackers to identify vulnerabilities.

The hacker provided a Telegram account address and Curry and other researchers engaged them in a separate conversation, sharing screenshots of multiple pages of Uber’s cloud providers to prove they hacked.

The Associated Press tried to contact the hacker on the Telegram account where Curry and the other researchers spoke with them. But no one responded.

A screenshot posted to Twitter and confirmed by researchers shows a chat with the hacker in which they say they obtained an administrative user’s credentials and then used social engineering to access Uber’s internal network.

In 2016, a massive cybersecurity breach at Uber saw hackers steal the personal data of 57 million Uber customers and drivers.

As a result, Uber was forced to pay $148 million to settle a lawsuit with all 50 states and the District of Columbia over the violation.



Source Link

COMMENTS

Name

Africa,973,Americas,4395,Art & Culture,16280,Arts,6830,Arts & Design,1939,Asia,3622,Automobile,586,Baseball,857,Basketball,701,Books,4252,Business,5737,Celebrity,2631,Cricket,648,Crime,158,Cryptocurrency,2264,Dance,735,Defense,836,Diplomatic Relations,2496,Economy,1419,Editorial,260,Education,1532,Elections,308,Energy & Environment,3213,Entertainment,23743,Environment,4004,Europe,4589,Faith & Religion,234,Family & Life,817,Fashion & Style,3703,Finance,22154,Food & Drink,4180,Football,1326,Games,97,Gossip,10283,Health & Fitness,4530,Health Care,979,Hockey,288,Home & Garden,917,Humour,994,Latin America,49,Lifestyle,18703,Media,527,Middle East,1777,Movies,2068,Music,3008,Opinion,4227,Other,13373,Other Sports,5515,Political News,11322,Political Protests,2324,Politics,18946,Real Estate,2375,Relationship,106,Retail,3115,Science,3000,Science & Tech,11299,Soccer,395,Space & Cosmos,467,Sponsored,4,Sports,13726,Technology,3828,Tennis,751,Theater,1994,Transportation,313,Travel,2880,TV,4034,US,1644,US Sports,1481,Video News,3531,War & Conflict,1069,Weird News,996,World,18367,
ltr
item
Newsrust - US Top News: Uber deals with 'cybersecurity incident' after hacker appears to breach its system
Uber deals with 'cybersecurity incident' after hacker appears to breach its system
https://assets2.cbsnewsstatic.com/hub/i/r/2022/07/10/6b2a4c31-c3c2-4bf4-9a06-50b766fb66c9/thumbnail/1200x630/6ed8be4487fb08d40203c3e55a1f2a76/download.jpg
Newsrust - US Top News
https://www.newsrust.com/2022/09/uber-deals-with-cybersecurity-incident.html
https://www.newsrust.com/
https://www.newsrust.com/
https://www.newsrust.com/2022/09/uber-deals-with-cybersecurity-incident.html
true
732247599994189300
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share to a social network STEP 2: Click the link on your social network Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy Table of Content