Case File

One Contractor's Phone, One Uber Breach

A company with a dedicated security team, significant resources and a mature incident response process was still breached through one contractor's phone. That is the point of including this case: scale does not remove the human element from security, it just relocates where the weak point sits.

What Happened

In September 2022, an attacker linked to the Lapsus$ hacking group bought a set of VPN credentials belonging to an external Uber contractor, most likely obtained on a dark web marketplace rather than through any direct action against the contractor. Armed with a valid username and password, the attacker began repeatedly attempting to log in, each attempt triggering a two-factor authentication push notification on the contractor's phone.

The Damage Caused

The contractor initially declined the flood of prompts. The attacker then contacted them over WhatsApp posing as Uber IT support and convinced them to approve one. That single approval opened access to internal systems including Slack, Uber's finance and invoice management tools and a database of vulnerability reports submitted through its bug bounty programme. Customer data was not accessed and the codebase was not modified. The internal access itself was extensive nonetheless, extensive enough to become a major public breach disclosure.

What Caused the Breach

The technique is known as MFA fatigue (or MFA bombing): overwhelming a user with repeated authentication prompts until habituation or simple exhaustion leads them to approve one without thinking. It exploits a specific weakness in push-based two-factor authentication, that it trains users to treat "approve" as a reflexive response to an interruption rather than a deliberate security decision made once per login.

Layered onto that weakness was a straightforward social engineering call, an attacker impersonating internal support through a channel the contractor had no reason to distrust. Neither element required any technical sophistication once the stolen credentials were in hand.

What Could Have Been Done to Avoid the Issue

Number-matching MFA, where a user must enter a code shown on the login screen rather than simply tapping approve, closes this specific gap: a prompt with no code to match gives an attacker nothing to exploit through repetition. Hardware security keys and passkeys go further, since they cannot be approved through a fatigue attack at all.

For any organisation, including a private household or family office with staff or contractors holding access to shared systems, a clear policy that unexpected MFA prompts get reported immediately, not silently dismissed, closes the human half of this gap. The technical control and the reporting habit work best together, since neither one alone would have stopped this specific attack.

Every security measure involves a trade-off between protection and convenience. Where that balance should sit depends on the resources a realistic attacker would bring to bear against you specifically. For most people, a handful of consistent habits closes the majority of that gap. For those whose assets or profile make a determined, well-funded attacker plausible, a more considered approach becomes worth the investment.

At Executive Privacy Advisors, we build that approach around your specific threat profile rather than a generic checklist. We extend the same thinking to your whole household, not just one set of accounts.

Need your digital life secured?

Request an Assessment

Published by Executive Privacy Advisors.

This article is for general informational purposes only and does not constitute security, legal or risk advice. Services described are subject to assessment, licensing and availability in your area. Your circumstances may differ and you should seek a professional assessment before making decisions.

← Back to all Case Files