Uber, which started operations in 2019 and has since become one of the largest private transportation network companies in the world, is widely known for being banned after the trouble with taxi drivers in our country. However, this incident is actually the smallest incident that has happened to Uber.
About 4 years ago, Uber announced a CEO change in 2017. has admitted that the data of its 57 million users was stolen. Uber officials, who reported on the incident for a year, announced that they tried to fix the problem themselves, but were unsuccessful. In recent months, one of the company’s former executives gave information to the US government and the press, including Uber’s Turkey. He tried to make himself accepted by lobbying in almost all countries. popped up.
Uber hacked again

The company, which has been under constant attack from minor attacks since the last major hack, released a statement today. are the victims of a massive attack. and reported that law enforcement officers intervened in the incident. The authorities, who have issued another statement in recent hours, stated that all their systems are working and stated they could find no evidence that user information was stolen.
Anonymous users investigating such cyberattacks of the attack reached out to the hacker, who is only 18 years old, and got a lot of details about the attack. Let’s learn together how this very simple but effective attack is performed.
It all started with social engineering

Uber, a software company called Duo, is a world-renowned software company for its employees to “secure” access to their accounts. Multi-factor authentication (Multi Factor Authentication or MFA). Thanks to this system, even if you entered your information correctly, it would send you a verification code (or simply ask for your approval), increasing your security.
The hacker, who knows the system Uber uses, has social engineering Uber followed the employee and started to get to know itself. The hacker prepared his plans for his hunt and created a fake Uber login page. After the hacker obtained the victim’s credentials through this page, the last thing the hacker needed was MFA approval.
To the Uber employee consecutive login notifications for hours The hacker, who sent it in, then reached out to the employee via WhatsApp and said there was a glitch in the system. must approve one of the notifications told. The employee approved the report and the hacker infiltrated the system.
So what did the hacker achieve?
Screenshots posted by the hacker via an anonymous user
By sharing screenshots of the system he hacked, Hacker had taken over the account of a team worker who took necessary actions in case of emergency. In this way, all of the company’s Slack channels, records of previous cyber attacks, backup files even The hacker, who can even see the data of customers who spend money, almost also has access to the company’s AWS (Amazon Web Services) system. had unlimited access.
While the hacker doesn’t reveal what documents or information he received to those who spoke to him, many security experts also keep the hacker’s private data for users. may have collected as much data as the company’s financial data. is thinking.
Uber stated that they had reported the situation to the authorities and decided to provide more explanation. refused.
Click now for an affordable Disney+ membership!