Business

Young hacker tricks way into Uber’s system: reports

Company says no evidence incident involved access to sensitive data

Updated 3 years ago · Published on 17 Sep 2022 10:00AM

Young hacker tricks way into Uber’s system: reports
According to reports, online comments purported to be by the hacker indicated he targeted an Uber employee with notifications for more than an hour, then reached out via WhatsApp claiming to be a member of the company’s tech support team. – AFP pic, September 17, 2022

SAN FRANCISCO – Uber said yesterday it was investigating a “cybersecurity incident”, declining to comment on reports a young hacker had gained access to the ride-hailing company’s computer network.

Uber put out word of the breach late Thursday in a tweet, and a hacker claiming to be 18 years old then posted screenshots taken from inside Uber computers.

“He says that he simply – having already determined a valid username and password – tricked an Uber staff member into granting him access to internal systems,” independent cybersecurity analyst Graham Cluley said on his website.

Online comments purported to be by the hacker indicated he targeted an Uber employee with notifications for more than an hour, then reached out to the worker via WhatsApp claiming to be a member of the company’s tech support team.

“Many other companies are probably at risk of falling for a similar trick,” Cluley said.

Uber said yesterday that its services were all operational and that it had “no evidence that the incident involved access to sensitive data” such as users’ trip history.

Employee software tools shut down as a precaution were being gradually restarted, the San Francisco-based company added.

“There’s a reason cybersecurity experts say that the human is often the weakest link,” said Ray Kelly, a fellow at Synopsys Software Integrity Group in Silicon Valley.

“Whether it be phishing/SMS attacks or a simple phone call to get an employee to give up their credentials, ‘social engineering’ is going to be the easiest route for a malicious actor.” – AFP, September 17, 2022

Related News

Malaysia / 4mth

SMEs most vulnerable to data breaches and hacking – expert

Malaysia / 2y

Beware of ‘wedding invites’ carrying malware, says Bukit Aman

World / 2y

Rise of three-nation partnership to fight menace of cyber threats in region

Malaysia / 2y

What more must the authorities do to combat online scams?

Education / 2y

Kings and CSM set to drive cybersecurity education and research in the country

Malaysia / 2y

Padu security breach: Pikom urges govt to engage ‘crucial’ external expertise

Spotlight

Malaysia

Bersatu-PH tie-up a possibility as coalition seeks Malay support, analyst says

By Alfian Z.M. Tahir

Malaysia

Woman molested on her way home from work (video)

Malaysia

Court allows Daim's daughter to permanently keep passport

Malaysia

Santiago pokes holes in data centre hype, asks: Who really benefits?

By Alfian Z.M. Tahir

Malaysia

Jeweller vows to pursue Rosmah until ‘every penny’ is recovered as RM67.5m battle enters enforcement phase

Malaysia

Ambulance carrying two injured men crashes en route to hospital after MPV collision in Besut

Malaysia

Man blames 'lack of love' for sexual assault on teens

Business

BNM's OPR to stay at 2.75 pcent in 2026 amid strong domestic demand - Kenanga IB

Malaysia

Missing jewellery: Rosmah ordered to pay RM67.5 million

You may be interested

Business

Unemployment rate rises to 3.0 per cent in April 2026 - DOSM

Business

Ringgit holds firm against major currencies as markets await key US inflation data

Business

Ringgit holds firm despite US inflation shock as markets brace for Federal Reserve decision

Business

BNM's OPR to stay at 2.75 pcent in 2026 amid strong domestic demand - Kenanga IB

Business

Open fibre sues Bank Pembangunan, six others in RM2b claim over Aries telecoms liquidation

Business

AI should support human thinking, not replace it - MDEC CEO