Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Contractors Need the Same Security as Employees

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.

The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts. Contractors often have similar access to employees but weaker oversight.

Why contractors deserve equal security

Contractors, consultants and temporary staff often:

  • Use their own devices, which may be infected with password-stealing malware.
  • Are exempt from some security policies "to keep things simple."
  • Keep access after their engagement ends.

Attackers know contractor accounts are easier targets.

The business impact

  • Full breach starting from a contractor account.
  • Access lingering after projects end.
  • Unclear accountability when contractors work through third-party firms.

Questions to ask your team

  • Do contractors have the same MFA and device requirements as employees?
  • Can contractors access company data from personal, unmanaged devices?
  • How quickly is contractor access removed when engagements end?
  • Do we review contractor access regularly?

What good looks like

The same or stricter sign-in protection for contractors, limited access on unmanaged devices, access with automatic expiration dates, and quarterly reviews.

The decision

Ask for the number of active contractor and guest accounts and how many haven't been used in 90 days. It's a simple metric with an immediate cleanup opportunity.

uber hack 2022 impactUber MFA fatigue2022

More on this story