Responding to last week's hack, Uber says a contractor's account was breached by Lapsus$-linked hackers and exposed HackerOne bug reports were remediated
Uber had taken internal systems offline after a breach that was described as potentially broad, while reporting no evidence that sensitive user information had been accessed. The earlier report that the intruder downloaded HackerOne vulnerability reports makes Uber’s remediation update more consequential than a routine account-reset notice.
The incident also lands against Uber’s expanded FTC settlement over its 2016 breach, which required the company to retain bug-bounty reports and created consequences for future disclosure failures.
First-order effects
Uber must treat the breached contractor account and the exposed HackerOne reports as an active security-response issue; it says the reported vulnerabilities have been remediated.
HackerOne researchers whose reports were accessed lose the confidentiality of their findings, even as Uber closes the reported issues.
Second-order effects
Uber’s security and legal teams face a more demanding incident record because the company’s prior FTC settlement specifically covers retention of bug-bounty reports and future disclosure compliance.
Bug-bounty programs become a more prominent internal access-control target: exposure of report archives can reveal a company’s security weaknesses even when user data is not shown to be accessed.
Third-order effects
The episode points to vulnerability-disclosure systems being treated not only as remediation pipelines but as sensitive internal repositories requiring the same account and vendor-access controls as other high-value corporate systems.
The trend: Security teams are tightening controls around contractor access and vulnerability-report archives as breach impact increasingly includes exposure of defensive intelligence, not only customer data.
Uber also suggests(?) they believe LAPSU$ to be the culprit behind the Rockstar games breach (and subsequent Grand Theft Auto leaks) https://twitter.com/...
Uber and Rockstar Games are in close coordination with the FBI and US Department of Justice amid both companies being hacked. The group known as Lapsus were seemingly involved with the attacks which have previously targeted Microsoft & Nvidia in 2022. https://www.uber.com/... htt…
The law means I can't tweet the name, but there is a definite Twitter whispering campaign attempting to link one of the British teens alleged to be part of Lapsus$ with the most recent Uber and Rockstar / GTA6 hacks.
Uber has released a statement regarding their recent breach. They state they believe the breach to be conducted by LAPSU$ extortion group (or someone affiliated with the group). Uber official press release: https://www.uber.com/...
*Contractors need the same tools & education as FT staff* Uber claims a contractor was the initial access point in the hack. Lots of orgs leave contractors out of sec education and technical tools (like right MFA, pw manager, etc). Time for that to change. https://www.uber.com/..…
Uber has attributed its cybersecurity incident to the Lapsus$ group, and adds that the attacker managed to download or access some Slack messages and invoice-related data: https://www.uber.com/...
Uber shares detail on last week's breach: “ It is likely that the attacker purchased the contractor's Uber corporate password on the dark web, after the contractor's personal device had been infected with malware, exposing those credentials” https://www.uber.com/...