Entra ID & IdentityIncident TeardownsRetrospectives

Uber Breached via MFA Fatigue (Sept 2022): A Contractor, a Push Storm and Hardcoded Admin Secrets

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.

On September 15, 2022, Uber disclosed a network security incident. An attacker had gained access to internal systems including its Slack workspace, cloud consoles and security tools, and posted a message announcing the breach in Uber's own Slack.

How it happened

According to Uber's account, the attacker — believed to be associated with Lapsus$ — likely bought a contractor's Uber credentials from the dark web after the contractor's personal device was infected with malware. The account was protected by MFA. The attacker repeatedly tried to sign in, generating many MFA push requests. The contractor eventually approved one. Reports indicated the attacker also contacted the contractor on WhatsApp, posing as Uber IT, urging them to accept.

Once inside, the attacker found network shares containing a PowerShell script with hardcoded administrator credentials for Uber's privileged access management system. That gave access to secrets for other systems, including cloud consoles and internal tools.

Why it mattered

  • MFA fatigue worked against a large, security-conscious company.
  • Contractors had meaningful access with less oversight.
  • A single script with hardcoded admin credentials turned a limited breach into broad access.
  • The vault itself was the prize. Compromising the privileged access management system unlocked everything.

Lessons in hindsight

  • Number matching and phishing-resistant MFA for all users, including contractors.
  • Scan file shares and repositories for secrets.
  • Protect privileged access systems with the strongest controls and separate administration.
  • Apply the same Conditional Access to contractors and guests as employees.
  • Infostealers on personal devices are a major source of credentials — require managed devices for access.

In hindsight

Uber's 2022 breach came six years after its 2016 breach — also traced to exposed credentials. The technique — buy credentials, spam MFA, pivot via secrets — became standard for the next wave of identity-focused attacks.

uber hack 2022Uber MFA fatigue2022

More on this story