Uber says hacker group Lapsus$ behind cybersecurity incident

avatar
Đã xác minh Truyền thông
· Views 406

Washington (CNN Business)Uber has linked the cybersecurity incident it disclosed last week to hackers affiliated with the Lapsus$ gang, a group accused of numerous high-profile corporate data breaches. The company also said the attackers were able to download or access company Slack messages and invoice-related data from an internal tool.

In a blog post on Monday, Uber (UBER) said the attackers first gained access to the company's systems when they successfully convinced a contractor to grant a multi-factor authentication challenge. The contractor's network password had likely been obtained separately on a dark web marketplace, Uber said.
"From there, the attacker accessed several other employee accounts which ultimately gave the attacker elevated permissions to a number of tools, including G-Suite and Slack," the blog post said. "The attacker then posted a message to a company-wide Slack channel, which many of you saw, and reconfigured Uber's OpenDNS to display a graphic image to employees on some internal sites."
    The attacker did not access user-facing systems, user accounts, databases containing personal information or the code that powers Uber's products, the company said. But it added the investigation is continuing in coordination with law enforcement and multiple cybersecurity firms.
      The blog post marks the first time Uber has publicly attributed the incident to the Lapsus$ gang, which targeted Microsoft earlier this year and is also accused of attacking Nvidia, Okta and other companies.
      Uber added that in response to the breach, it is strengthening its multifactor authentication policies and has reset employee access to internal tools.

      Tuyên bố miễn trừ trách nhiệm: Quan điểm được trình bày hoàn toàn là của tác giả và không đại diện cho quan điểm chính thức của Followme. Followme không chịu trách nhiệm về tính chính xác, đầy đủ hoặc độ tin cậy của thông tin được cung cấp và không chịu trách nhiệm cho bất kỳ hành động nào được thực hiện dựa trên nội dung, trừ khi được nêu rõ bằng văn bản.

      Bạn thích bài viết này? Hãy thể hiện sự cảm kích của bạn bằng cách gửi tiền boa cho tác giả.
      avatar
      Trả lời 0

      Tải thất bại ()

      • tradingContest