← Incident database

uber-2022 · Disclosed 2022-09-15

Uber: repeated MFA prompts and a contractor account

A contractor accepted one of repeated two-factor requests, enabling access to internal tools. Uber described the initial password acquisition as a likely explanation.

CredentialsEndpoint / session

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    The attacker logged in after a contractor accepted a two-factor request.

    [s1]What happened?
  • Assessment

    Uber assessed that malware on a personal device likely led to the password being sold.

    [s1]What happened?

Timeline

  1. Initial incident disclosure. [s1]

  2. Entry path and response update published. [s1]

Reported response

  • Reported fact

    Affected accounts were blocked or reset, keys rotated, and reauthentication required when tools were restored.

    [s1]How did we respond?

Evidence relevant to prevention

Operational controls to inspect

Inspect MFA methods, repeated prompt handling, and coverage of contractor accounts, not only whether MFA exists.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

The exact password theft path is not established by the cited disclosure.

Sources

  1. [s1] Uber · Primary source

    Security update (September 19 update) ↗

    Published 2022-09-16 · Reviewed 2026-10-02