The Uber breach of 2022 raised some questions about how much progress large technology companies make on security between incidents. For the third time in eight years, hardcoded credentials played a role in an Uber breach. With plaintext credentials found in a PowerShell script, the attacker gained broad access to Uber’s systems. The teenaged attacker would go on to breach several other companies that month using similar techniques.
Background
Uber Technologies is one of the largest logistics and technology companies in the world, operating across more than 70 countries and serving hundreds of millions of users annually. By 2022, the company employed roughly 32,000 people and reported revenues of approximately $14.1 billion. Uber’s operations, like most of a similar size, depend on a broad cloud infrastructure, a global contractor workforce with remote VPN access to internal systems, and off-the-shelf security tooling that itself often becomes a high-value target once an attacker establishes a foothold.
Narrative
Point of Compromise
In September 2022, an attacker obtained the VPN credentials of Uber contractors via the dark web. , days before the attack.
Infostealers are a category of malware designed to silently harvest credentials and other authentication data from an infected device and package them for sale on criminal marketplaces. Group-IB, a Singapore-based threat intelligence firm, monitors the dark web and marketplaces containing stolen credentials from malware like infostealers.
After screenshots from the Uber hack were shared on Twitter, Group-IB located Uber employee credentials in the logs of two of the most popular infostealer malware families: Raccoon and Vidar. The firm noted that those logs were listed for sale on September 12 and 14, just a few days before the attack occurred. Uber’s own post-mortem corroborated this, stating that the contractor’s personal device had been infected with malware prior to the attack, exposing their credentials.

With these credentials, the only obstacle left was getting past Uber’s multi-factor authentication, which used Cisco Duo. Any login requests would need to be verified by the compromised user. The attacker launched an MFA fatigue attack, sending repeated requests to the contractor’s phone for over an hour. When the contractor did not approve, the attacker contacted them on WhatsApp, claimed to be from Uber’s IT team, and told them the requests would stop if they approved one. The contractor did so, and the attacker was able to connect to Uber’s internal network.
Once on the VPN, the attacker scanned the internal network and quickly found an open Windows share. A PowerShell script on this network share contained administrator credentials associated with Thycotic, a vendor that makes privileged account management software. We suspect, based on the outcome, that the product the attacker got access to was Thycotic Secret Server, which would have functioned as an enterprise password vault for shared credentials used by administrators - the most sensitive credentials in the enterprise.
As for the network share, we don’t have any details on what the purpose of it was, but it is common to find open Windows shares on corporate networks and it is common to find hardcoded credentials in scripts on these shares. It is possible that this share had to be accessible for normal operation of an Active Directory environment (like NETLOGON), or it could have been a share that should have been better protected by tighter permissions or network segmentation.
With these newfound credentials, the attacker was able to get access to a myriad of systems, including Uber’s AWS environment, GCP, VMware vSphere, GSuite admin panel, SentinelOne XDR, and HackerOne bug bounty dashboard. The attacker announced the breach on Uber’s internal Slack, reconfigured internal domain name system (DNS, managed via Cisco’s OpenDNS service) to display explicit images on internal sites, and commented on HackerOne vulnerability submissions using a compromised account. Employees initially assumed it was a joke.
Who Did This?
Unlike many breaches where attribution remains contested, the identity of the attacker in this case was very clear. Going by “TeaPotUberHacker” and “teapots2022”, the attacker spoke to the New York Times the day after the attack, claiming to be 18.
Security researchers and law enforcement were well acquainted with the attacker before the Uber breach. Arion Kurtaj, was a British teenager operating under aliases including White, Breachbase, and WhiteDoxbin. Kurtaj was affiliated with the Lapsus$ ransomware group, known for its aggressive social engineering attacks. City of London Police had already arrested Kurtaj several times, for attacks against mobile telecom BT/EE and NVIDIA. Each time, due to his age, he was released on bail.
Kurtaj had previously purchased Doxbin, a personal-information-sharing site, in late 2021. He relinquished control in January 2022 and leaked the entire Doxbin dataset to Telegram. The Doxbin community retaliated by publishing his personal information, which is ultimately how Bloomberg’s researchers connected his online aliases to his real identity months before the Uber breach. The information released about Kurtaj alleged he had access to $14M in cryptocurrency. This information, combined with a death threat emailed to his mother, resulted in the City of London Police deciding to take him and his mother into protective custody.
While in custody, at a hotel paid for by the police, Kurtaj managed to pull off two additional attacks - the 2022 Uber breach and the Rockstar Games breach that leaked information about the unreleased and (still today) hotly anticipated video game, Grand Theft Auto VI.
Kurtaj’s reason for breaching Uber was simple. In his interview with NYT, he said he targeted Uber specifically because he felt the company had weak security. There is no evidence he attempted to sell the bug bounty reports he accessed or otherwise monetize the breach.
Impact
Since no ransom was requested or paid, and no information was leaked, there were no direct losses for Uber. The stock dropped by 5% the day the breach was made public, but recovered soon after. Uber never formally disclosed a breakdown of remediation costs or legal expenses, as there was likely no material impact requiring more detailed disclosure.
The attacker’s access was broad enough to cause immediate operational disruption. Most of Uber’s enterprise credentials would be considered compromised and would have to be painstakingly changed. Most concerningly, access to SentinelOne and HackerOne gave the attacker visibility into Uber’s vulnerabilities and security posture.
For the public, the more lasting impact was the attention the breach brought to MFA fatigue as an accessible and repeatable attack technique. The attacker used the same method four days later when breaching Rockstar Games, leading to a leak of 90 clips of unfinished Grand Theft Auto VI footage.
Legacy & Lessons Learned
Kurtaj was arrested yet again, in September 2022, by the City of London Police. He was convicted on twelve counts in August 2023, covering unauthorized access, blackmail, and fraud across multiple victims including Uber, Rockstar Games, Nvidia, BT/EE, and Revolut.
For the initial access to Uber’s systems, hardware-based FIDO2 authentication (e.g. security keys) could have removed ‘MFA bombing’ as an option for the attacker. Infostealers can unfortunately also steal logged-on sessions, so assume defenses at this stage will fail.
Assess the files available on portions of the network where compromised accounts might land. In a Windows network, some shares, like NETLOGON must be open, as this is where many post-logon scripts live by default. These startup scripts often contain valuable plaintext credentials, and this is still common practice at many companies today. Minimize Windows file share use and inspect the files available with EVERYONE/Full Control permissions.
Access to sensitive credentials in a password vault should be compartmentalized - avoid any ‘master’ accounts with access to all company credentials. Furthermore, require additional authentication and authorization controls to limit access to high value systems like secrets managers.
Finally, monitor for suspicious attack behavior. Look for systematic data access or exfiltration. MFA bombing attacks should also trigger alerts.
Appendix A: Control Failures and Framework Mappings
ATT&CK Navigator Summary: Primary Tactics Leveraged
MITRE D3FEND
Appendix B: References
Breach Information
https://www.nytimes.com/2022/09/15/technology/uber-hacking-breach.html
https://infosecwriteups.com/case-study-the-uber-hack-d9453d275060
https://www.darkreading.com/cyberattacks-data-breaches/uber-breachexternal-contractor-mfa-bombing-attack
https://www.acecloudhosting.com/blog/uber-cyberattack-lapsus-2022/
https://investorplace.com/2022/09/uber-stock-falls-5-on-major-cybersecurity-breach/
Social Engineering for MFA
https://techcrunch.com/2022/09/19/how-to-fix-another-uber-breach/
https://thehackernews.com/2022/09/uber-claims-no-sensitive-data-exposed.html
https://m1le5.medium.com/case-study-the-uber-hack-d9453d275060
https://group-ib.medium.com/what-group-ib-found-about-the-uber-hack-c47cad571ea8
Bug Bounty Breach
Attacker Arrest
https://thehackernews.com/2023/08/two-lapsus-hackers-convicted-in-london.html
https://techcrunch.com/2022/03/24/london-police-lapsus-arrests/
https://techcrunch.com/2022/04/01/uk-police-teenagers-lapsus/
https://techcrunch.com/2022/09/26/london-police-arrest-uber-rockstar/
https://www.theregister.com/2023/12/21/lapsus_teens_sentenced/
https://www.axios.com/2023/08/23/lapsus-hacker-uber-nvidia-rockstar-trial
https://www.bankinfosecurity.com/teen-uber-hacker-sent-to-indefinite-hospital-detention-a-23962
Appendix C: Full Timeline
Late 2021 - Attacker purchased Doxbin, a personal-information-sharing site, before relinquishing control in January 2022 and leaking the entire Doxbin dataset to Telegram. The Doxbin community retaliated by doxxing him, which is ultimately how Bloomberg’s researchers located him
January 2022 - Attacker and one accomplice are arrested and released under investigation
September 12 and 14, 2022 - Infostealer logs containing Uber contractor credentials are put up for sale on dark web marketplaces. The infostealers involved are identified as Raccoon and Vidar.
September 15, 2022 - Uber posts a public statement: “We are currently responding to a cybersecurity incident. We are in touch with law enforcement and will post additional updates here as they become available.”. Attacker posts on Uber’s internal Slack announcing the breach, also comments on a HackerOne submission with the compromised account. Employees initially thought it was a joke. Additionally, Uber’s OpenDNS is reconfigured to display an explicit image on internal sites.
September 16, 2022 - HackerOne disabled Uber bug bounty program. The attacker speaks to the New York Times, claiming to be 18 years old and stating they targeted Uber because the company had weak security. The attacker also states they are considering leaking Uber’s source code.
September 18, 2022 - The attacker posts 90 GTA VI video clips on a forum, claiming the same access method.
September 19, 2022 - Full post-mortem is published and the attack is attributed to Lapsus$ and confirming no evidence of customer data access. The Rockstar Games breach is publicly confirmed the same day.
September 22, 2022 - City Of London Police arrest a 17 year old in Oxfordshire on suspicion of hacking, as part of an investigation by UK’s National Crime Agency’s National Cyber Crime Unit
August 2023 - Attacker is convicted on 12 counts, including unauthorized access, blackmail, and fraud, covering breaches on Uber, Rockstar Games, Nvidia, BT/EE, and Revolut.
December 21, 2023 - Attacker is sentenced to indefinite detention in a secure hospital after psychiatrists assess him as unfit to stand trial. A mental health assessment during sentencing notes that he continued to express intent to return to cybercrime as soon as possible.







