Uber...again

Author
Discussion

juice

Original Poster:

8,771 posts

288 months

Friday 16th September 2022
quotequote all
https://www.zdnet.com/article/uber-security-breach...

Looks like an employee got done by Social engineering and push notification spamming. Cannot quite believe they gave their network creds out to someone who messaged them claiming to be from Uber's IT...What's worse is the fact that network admin creds were on a bloody network share !!

That's one app deleted from my phone, they cannot be trusted with people's data imo.


Mr Penguin

2,562 posts

45 months

Friday 16th September 2022
quotequote all
This is basic stuff and Uber keep some of the most private information people can have. Hopefully this is a kick up the arse for them.

Taita

7,713 posts

209 months

Friday 16th September 2022
quotequote all
That is an absolutely wild level of compromise.

Proof that humans are the hardest part to secure.

eeLee

837 posts

86 months

Friday 16th September 2022
quotequote all
Twitter was done via Slack some time back too. They had some credentials in there for "God" mode that led to some high-profile accounts punting a crypto pyramid pump-and-dump scam.

Stupid is as stupid does, my friend once said. Repeatedly. While eating a box of chocolates.