First reportedSeptember 17, 2022
ActivitySeptember 15, 2022
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Uber
  • Uber employees and internal systems potentially accessed during the incident

Initial access

  • stolen_creds
  • phishing

Impact

  • data_theft
  • unknown

Attribution

Lapsus$ (suspected/associated) med confidence

Public reporting and incident analyses frequently associate the incident with Lapsus$ tactics; Uber’s disclosure focuses on access method and remediation.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1078: The attacker used valid credentials to access internal systems.
  • T1566: The incident involved social engineering to obtain or reuse credentials and drive access.

Mitigations

Now

  • Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.

Soon

  • Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.

Later

  • Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.

Detection ideas

Alert on anomalous authentication patterns

Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.

Data sources: IdP sign-in logs, SSO audit logs, VPN authentication logs

Detect risky account recovery and MFA changes

Alert when MFA factors are reset/added, recovery email/phone is changed, or helpdesk performs high-risk password resets outside normal hours.

Data sources: IdP audit logs, Helpdesk/ticketing logs

Sources