Uber's been hacked by an 18 year old, go figure

Hacker using a phone and pc while wearing a ski mask.
(Image credit: Getty- South_Agency)

It appears Uber has been hacked by an 18-year-old. As discovered Thursday, the hijacker managed to gain full admin access to the company's AWS, Duo, OneLogin, G Suite, VMware vSphere domain accounts, and more. They even bagged Uber's source code and have sent out screenshots to prove it.

Not a great time for Uber then. But what really gets me is how people are meant to have reacted when asked to stop interacting with the hacker on Slack—if you work in IT you might need to ask a friend to hold you back for this one.

According to The New York Times, the person responsible for the Uber hack claims to have gained access simply by sending a text to an Uber employee pretending to be from the company's corporate IT team. The hacker, if we can even call them that, just persuaded the employee to send them their login credentials and, boom, full access granted.

Yuga Labs engineer Sam Curry posted on Twitter about the event, having spoken to the apparent hacker, who claims to be just 18 years old. They sent some pretty legitimate-looking screenshots of internal systems to prove their quarry.

Curry spoke to some Uber employees as to their experience: "At Uber, we got an 'URGENT' email from IT security saying to stop using Slack," one employee said. "Now anytime I request a website, I am taken to a REDACTED page with a pornographic image and the message 'F*** you wankers'."

Another employee said that, "Instead of doing anything, a good portion of the staff was interacting and mocking the hacker thinking someone was playing a joke. After being told to stop going on slack, people kept going on for the jokes."

The Slack channel was finally taken offline after one message read "I announce I am a hacker and Uber has suffered a data breach." It also went on to list a bunch of systems they were claiming to have access to. What's really wild is that since there doesn't seem to be any rhyme or reason behind the attack "it seems like maybe they’re this kid who got into Uber and doesn’t know what to do with it, and is having the time of his life,” Curry jokes.

Ars Technica reports that this isn't the first time Uber has been involved in a data breach. Back in 2016 Uber allegedly failed to report a massive data breach in which 57 million customer and driver names, email and phone numbers were stolen. The company allegedly failed to report the incident to the Federal Trade Commission, instead opting to pay the hackers a $100,000 bug bounty so they would delete the data and sign an NDA, and out of embarrassment passing it all off as part of a security test.

That time, it resulted in one of Uber’s top security execs, Joe Sullivan, being fired, though his lawyers say he was made a scapegoat for the downfalls of other employees

Your next upgrade

(Image credit: Future)

Best CPU for gaming: The top chips from Intel and AMD
Best gaming motherboard: The right boards
Best graphics card: Your perfect pixel-pusher awaits
Best SSD for gaming: Get into the game ahead of the rest

The recent attack is currently under investigation with Uber's official Twitter account stating Thursday, "We are currently responding to a cybersecurity incident. We are in touch with law enforcement and will post additional updates here as they become available."

How people haven't figured out that giving your password out is a terrible idea by now, I'll never know. They call it social engineering, but attacks like this are so excruciatingly low effort, a title like that is frankly an insult to engineers. 

Bottom line? Please don't give your passwords out, even if someone claims to be from IT. That team should already have access to your account in case you forget your password. 

Katie Wickens
Hardware Writer

Screw sports, Katie would rather watch Intel, AMD and Nvidia go at it. Having been obsessed with computers and graphics for three long decades, she took Game Art and Design up to Masters level at uni, and has been rambling about games, tech and science—rather sarcastically—for four years since. She can be found admiring technological advancements, scrambling for scintillating Raspberry Pi projects, preaching cybersecurity awareness, sighing over semiconductors, and gawping at the latest GPU upgrades. Right now she's waiting patiently for her chance to upload her consciousness into the cloud.

Read more
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
 In this photo illustration a novelty Bitcoin token is photographed on a US Dollar bank note, on January 4, 2025 in Bath, England. The Cryptocurrency market has recently received a significant boost by the election of Donald Trump with hopes of the start of a policy framework that could see Bitcoin as a strategic asset
Man charged with $65,000,000 worth of cryptocurrency heists was reportedly discovered through chatting on Discord with a company they allegedly stole from
A Path of Exile 2 sorceress casting flaming skulls in a hellish landscape
'We are incredibly sorry': Path of Exile 2 devs apologise for data breach that saw 66 accounts snatched and personal info potentially stolen
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
Latest in Security
An FBI wanted poster for alleged hacker Zhou Shuai.
US Justice Dept announces $10 million bounty on at-large 'hacker-for-hire' cabal it says targeted China critics, religious missionaries, and the Treasury
Kinzie, in an FBI jacket, uses a computer with the logo of the Third Street Saints on it
Have I Been Pwned adds over 284 million compromised passwords from latest breach
A still from a YouTube video of Senator Mark Warner speaking
Telecoms hack on US government officials is 'worst in nations history' and 'the barn door is still wide open' says senator
HDMI cable
Hackers can wirelessly spy on your display by collecting HDMI signal leaks and churning them through an AI, but I wouldn't break out the tin foil just yet
Computer code and text displayed on computer screens. Photographer: Chris Ratcliffe/Bloomberg
Forcing users to periodically change their passwords should go the way of the dodo according to the US government
An original Apple Macintosh Model M0001, as they celebrate 40th anniversary, is on display in between 2024 Apple models at the independent Apple products store chain Amac, on January 24, 2024 in Utrecht, The Netherlands. Based on the Motorola 68000 microprocessor, the Macintosh was the first successful mouse-driven computer with a graphical user interface.
Major browser providers scramble to patch an 18-year-old vulnerability affecting MacOS and Linux systems but Windows remains gloriously immune
Latest in News
Gabe Newell in a Valve promotional video, on a yacht.
Go ahead and complain the discounts aren't as steep as they used to be, but Steam just had its biggest year ever for seasonal sales
Valve Steam Deck OLED handheld PC
'The future of hardware at Valve is bright': Valve celebrates the success of Steam Deck and Steam OS
Key art of the videogame Lunacid, showing a pale, long haired knight in purple armor contemplating a purple, flaming sword surrounded by the different phases of the moon.
One of my favorite indie RPGs is getting a follow-up made with FromSoftware's 25-year-old Super Mario Maker for first person dungeon crawlers
Kingdom Come: Deliverance 2 image - Henry riding a pink and blue striped horse while holding a fish
Kingdom Come: Deliverance 2 now has Steam Workshop support, and of course one of the first mods lets you adjust the 'jiggle physics'
Still image of Bastion holding a bird, taken from Microsoft's Copilot for Gaming reveal trailer
Microsoft unveils Copilot for Gaming, an AI-powered 'ultimate gaming sidekick' that will let you talk to your console so you don't have to talk to your friends
Erenshor - A player and two simulated MMO party members stand on a plateau in front of a yellow landscape
This RuneScape-looking 'simulated MMORPG' has all the nostalgia without the drama because all the other 'players' are NPCs