Lapsus$: The Infamous Hacker Group behind Uber is an Old Player

Lapsus$: The Infamous Hacker Group behind Uber is an Old Player

Lapsus$ is an old player in the cyberattack landscape with Microsoft, Samsung, and Nvidia under its belt.

Uber's computer network was breached by a cyberattacker last Thursday, who Uber now says hacked into the account of an EXT contractor after likely purchasing the employee's credentials from the dark web. In a blog post Monday, Uber said it is likely the contractor's device had been infected with malware, leading to those credentials becoming exposed. Though Uber has online safety precautions in place for employee logins, the contractor unknowingly accepted a verification notification that ultimately granted the attacker access, the ride-share company said. From there, the attacker accessed several employee accounts and tools such as G-Suite and Slack.

Uber laid the blame on hacking group Lapsus$, which used similar attacks to breach Microsoft, Cisco, Samsung, Nvidia, Okta, and others in 2022. Lapsus$ was most recently reported to have been responsible for breaching Rockstar Games last Sunday and leaking early gameplay footage of Grand Theft Auto VI. Uber also confirmed a report last week that the hacker sent a message to a company-wide Slack channel and "reconfigured Uber's OpenDNS to display a graphic image to employees on some internal sites."

Uber says it immediately worked to respond to the security breach to protect internal systems and user data, including identifying employee accounts that were compromised and either blocking their access to Uber systems or requiring a password reset; disabling several internal tools; resetting access to many internal services; locking down the codebase; requiring employees to re-authenticate when access was restored, and adding internal environment monitoring "to keep an even closer eye on any further suspicious activity."

Uber said it is closely working with the FBI, the US Department of Justice, and "several leading digital forensics firms" on the ongoing investigation. The attack on Thursday led Uber to temporarily take down several internal communications and engineering systems, and it instructed employees not to use Slack. By Friday morning, Uber, Uber Eats, Uber Freight, and Uber Drive were all up and running, and Uber was bringing back online its internal software tools.

Related Stories

No stories found.
logo
Analytics Insight
www.analyticsinsight.net