{"id":48505,"date":"2022-09-19T21:24:55","date_gmt":"2022-09-19T21:24:55","guid":{"rendered":"https:\/\/www.darkreading.com\/attacks-breaches\/uber-breach-external-contractor-mfa-bombing-attack"},"modified":"2022-09-19T21:24:55","modified_gmt":"2022-09-19T21:24:55","slug":"uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/","title":{"rendered":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5e19933b34346704\/6328cf563a97082c2920ffbd\/uber2_Sundry_Photography_shutterstock.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Uber has attributed last week&#8217;s massive breach at Uber to the notorious Lapsus$ hacking group and released additional details on the attack. Researchers say the incident&nbsp;has highlighted the risks that can come from trusting too much in&nbsp;multifactor authentication (MFA), as well as unmanaged risk around cloud-service adoption.<\/p>\n<p>In an update on Monday, Uber laid out the attribution:&nbsp;&#8220;We believe that this attacker (or attackers) are affiliated with a hacking group called <a href=\"https:\/\/www.theverge.com\/22998479\/lapsus-hacking-group-cyberattacks-news-updates\" target=\"_blank\" rel=\"noopener\">Lapsus$<\/a>, which has been increasingly active over the last year or so.&#8221; Uber&#8217;s announcement&nbsp;pointed to other companies that had been targeted by the notorious gang&nbsp;via similar techniques, including Cisco,&nbsp;Microsoft, Nvidia, <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/ransomware-group-s-claim-that-it-hacked-okta-prompts-concerns-of-another-solarwinds\" target=\"_blank\" rel=\"noopener\">Okta<\/a>, and&nbsp;Samsung,<\/p>\n<p>Lapsus$ has <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/chaotic-lapsus-quiet-threat-persists\" target=\"_blank\" rel=\"noopener\">attracted considerable attention<\/a> in recent months for its brazen attacks on some of the world&#8217;s largest and well-known companies. One well-known tactic that the group has been known to use is co-opt MFA-circumventing tools into its attack chain. <\/p>\n<p>And indeed,&nbsp;Uber on Monday said the attacker who&nbsp;<a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/hacker-pwns-uber-via-compromised-slack-account\" target=\"_blank\" rel=\"noopener\">breached its network<\/a> last week had first <a href=\"https:\/\/www.uber.com\/newsroom\/security-update\/\" target=\"_blank\" rel=\"noopener\">obtained the VPN credentials of an external contractor<\/a>,<br \/>\nlikely by purchasing them on the Dark Web. The attacker then repeatedly tried to log in to the Uber account using the illegally obtained credentials, prompting a two-factor login approval request each time.&nbsp;<\/p>\n<p>After the contractor&nbsp;initially blocked those requests,&nbsp;the attacker contacted the target on WhatsApp posing as tech support, telling the person to accept the MFA prompt \u2014 thus&nbsp;allowing the attacker to log in.<\/p>\n<p>&#8220;The Uber breach appears to be a result of an MFA fatigue attack, also referred to as an MFA bombing attack,&#8221; says Duncan Greenwood, CEO of Xage. &#8220;It\u2019s a technique in which hackers send multiple authentication approval requests to a secondary device like a mobile phone, in hopes that a user unintentionally provides access, or grows so frustrated that they eventually approve a request.&#8221;&nbsp;<\/p>\n<h2 class=\"regular-text\">Remediation Process Begins<\/h2>\n<p>Once in,&nbsp;the attacker <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/attacker-apparently-didnt-breach-single-system-pwn-uber\" target=\"_blank\" rel=\"noopener\">breached multiple internal systems<\/a>, and Uber is currently in the process of doing an impact analysis, the company said: &#8220;The attacker accessed several other employee accounts, which ultimately gave the attacker elevated permissions to a number of tools, including G-Suite and Slack.&#8221;<\/p>\n<p>The company said the attacker does not appear to have made any changes to its codebase, nor does&nbsp;he appear to have access to&nbsp;any customer or user data stored by cloud providers. The attacker did appear to have downloaded some internal Slack messages and accessed or downloaded an internal tool that Uber&#8217;s finance team uses to manage invoices. Though the attacker also accessed a database of vulnerability disclosures in its platform submitted via external researchers through the HackerOne bug-bounty program, all the bugs have been remediated, Uber said.<\/p>\n<h2 class=\"regular-text\">Breach Shows MFA&#8217;s Weaknesses<\/h2>\n<p>Greenwood describes MFA fatigue attacks as being a very effective tactic for breaching target organizations. He says his company has observed attackers typically sending frequent MFA requests in the middle of the night or sending less frequent requests over a few days.&nbsp;<\/p>\n<p>&#8220;Either way, in traditional MFA architectures, all it takes is just one approved request for a hacker to access internal systems, from which they can further infiltrate the target organization,&#8221; he says.<\/p>\n<p>Uber&#8217;s security practices are sure to come under scrutiny because of the breach. But the reality is that the company was the victim of practices that are common to many organizations, researchers note.<\/p>\n<p>Patrick Tiquet, vice president of security and architecture at Keeper Security, says the Uber attack highlights a fundamental misconception around MFA&#8217;s strength as a method&nbsp;to secure access.&nbsp;<\/p>\n<p>&#8220;Although MFA adds a critical second layer of security to your accounts, the biggest misconception about MFA is that all forms are equally secure,&#8221; he says.<\/p>\n<p>One example of how MFA can fail is SIM card porting, aka <a href=\"https:\/\/www.darkreading.com\/edge\/sim-swapping-attacks-what-they-are-how-to-stop-them\" target=\"_blank\" rel=\"noopener\">SIM-swapping<\/a>,&nbsp;Tiquet notes. This is where attackers port a mobile number to a SIM card or device that they control to receive SMS messages or phone calls for the target number.&nbsp;<\/p>\n<p>&#8220;Use of SMS text messages as MFA should be discouraged and never used as MFA for high-value assets,&#8221; Tiquet says. &#8220;The use of an authenticator app, security key, or biometrics are stronger and more effective methods to protect your accounts.&#8221;&nbsp;<\/p>\n<p>Security researcher Bill Demirkapi explains that another very common misconception is that standard forms of MFA \u2014&nbsp;such as push, touch, and mobile \u2014 protect against social engineering. The reality is that MFA remains vulnerable to man-in-the-middle (MitM) attacks, he says.<\/p>\n<p>He notes that best practices include using phishing- and MiTM-resistant forms of MFA rather than&nbsp;time-based one-time passwords (TOTP), not centralizing access keys, and rotating keys regularly. On the latter point, organizations also often do not limit access keys to the minimum privileges required for the key&#8217;s intended purpose.&nbsp;<\/p>\n<p>&#8220;Uber may not have followed best practices, but many other companies don&#8217;t either,&#8221; he says. &#8220;The main point I&#8217;d like to drive home is the importance of not only investing into security for your organization, but specifically investing into these best practices as well.&#8221;<\/p>\n<p>It should be noted that the Uber breach is not the only high-profile hit in the last few days;&nbsp;the&nbsp;same Lapsus$ hacker who claimed responsibility in that incident (or at least someone using the same &#8220;Teapot&#8221; alias that the Uber hacker used) now appears to have also breached <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/rockstar-games-confirms-grand-theft-auto-6-breach\" target=\"_blank\" rel=\"noopener\">Take-Two Interactive&#8217;s Rockstar Games<\/a>, posting&nbsp;videos of an early development copy of the Grand Theft Auto 6 video game. In a message, the company <a href=\"https:\/\/twitter.com\/hacker_\/status\/1570582202697809920\" target=\"_blank\" rel=\"noopener\">acknowledged the breach<\/a> and said it was &#8220;extremely disappointed&#8221; to have details of the game leaked in advance of its release.<\/p>\n<h2 class=\"regular-text\">Cloud Service Adoption Increases Risk&nbsp;<\/h2>\n<p>MFA is not the only weak link for many companies.&nbsp;At a higher level, breaches like the one at Uber show the impact that rapid cloud services adoption and distributed work models are having on enterprise security strategies, says Russell Spitler, co-founder and CEO of Nudge Security.&nbsp;<\/p>\n<p>The move to a more distributed model has increased enterprise reliance on asynchronous communications tools such as Slack and WhatsApp in business-critical environments, he says. The rapid adoption of SaaS has created an unmanaged risk in the form of complex integrations between poorly managed services.<\/p>\n<p>&#8220;The recent breach at Uber points to the fact that security orgs are outpaced by the sprawling complexity of modern, distributed IT environments and sprawling digital supply chains,&#8221; Spitler notes. &#8220;This complexity creates opportunities for even the most novice of threat actors to gain access using compromised credentials and [finding] their way to critical assets.&#8221;<\/p>\n<p>Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/uber-breach-external-contractor-mfa-bombing-attack\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The ride-sharing giant says a member of the notorious Lapsus$ hacking group started the attack by compromising an external contractor&#8217;s credentials, as researchers parse the incident for takeaways.Read More <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/uber-breach-external-contractor-mfa-bombing-attack\">HERE<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[151],"tags":[],"class_list":["post-48505","post","type-post","status-publish","format-standard","hentry","category-darkreading-ti"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-09-19T21:24:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5e19933b34346704\/6328cf563a97082c2920ffbd\/uber2_Sundry_Photography_shutterstock.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack\",\"datePublished\":\"2022-09-19T21:24:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/\"},\"wordCount\":1122,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt5e19933b34346704\\\/6328cf563a97082c2920ffbd\\\/uber2_Sundry_Photography_shutterstock.jpg\",\"articleSection\":[\"DarkReading |TI\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/\",\"name\":\"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt5e19933b34346704\\\/6328cf563a97082c2920ffbd\\\/uber2_Sundry_Photography_shutterstock.jpg\",\"datePublished\":\"2022-09-19T21:24:55+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt5e19933b34346704\\\/6328cf563a97082c2920ffbd\\\/uber2_Sundry_Photography_shutterstock.jpg\",\"contentUrl\":\"https:\\\/\\\/eu-images.contentstack.com\\\/v3\\\/assets\\\/blt66983808af36a8ef\\\/blt5e19933b34346704\\\/6328cf563a97082c2920ffbd\\\/uber2_Sundry_Photography_shutterstock.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/","og_locale":"en_US","og_type":"article","og_title":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-09-19T21:24:55+00:00","og_image":[{"url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5e19933b34346704\/6328cf563a97082c2920ffbd\/uber2_Sundry_Photography_shutterstock.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack","datePublished":"2022-09-19T21:24:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/"},"wordCount":1122,"commentCount":0,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5e19933b34346704\/6328cf563a97082c2920ffbd\/uber2_Sundry_Photography_shutterstock.jpg","articleSection":["DarkReading |TI"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/","url":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/","name":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#primaryimage"},"thumbnailUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5e19933b34346704\/6328cf563a97082c2920ffbd\/uber2_Sundry_Photography_shutterstock.jpg","datePublished":"2022-09-19T21:24:55+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#primaryimage","url":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5e19933b34346704\/6328cf563a97082c2920ffbd\/uber2_Sundry_Photography_shutterstock.jpg","contentUrl":"https:\/\/eu-images.contentstack.com\/v3\/assets\/blt66983808af36a8ef\/blt5e19933b34346704\/6328cf563a97082c2920ffbd\/uber2_Sundry_Photography_shutterstock.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/uber-lapsus-targeted-external-contractor-with-mfa-bombing-attack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Uber: Lapsus$ Targeted External Contractor With MFA Bombing Attack"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48505","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=48505"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/48505\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=48505"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=48505"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=48505"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}