Uber Probing Hack of Third-Party Vendor After Employee Data, Source Code Leaked

Uber believes the leaked files are related to an incident at a third-party vendor and are unrelated to the company's security incident in September.

Advertisement
By Katrina Manson, Bloomberg | Updated: 13 December 2022 11:52 IST
Highlights
  • Data of 77,000 Uber employees was leaked in the hack
  • Hack targeted third-party vendor Teqtivity, which tracks IT equipment
  • Latest Uber breach follows September hack by extortion group Lapsus$

Uber faced a hack in September as well

Photo Credit: Reuters

Uber Technologies Inc. said it's investigating the hack of a third-party vendor that reportedly resulted in the leak of data from the ride-hailing company, including employee email addresses.

The vendor, Teqtivity, which helps manage and track information technology equipment such as phones and computers, on Monday confirmed the cyberattack.

More than 77,000 Uber employees' email addresses and other data, including alleged source code associated with mobile device management platforms used by Uber and Uber Eats, have been leaked as part of the recent hack, according to a report from Bleeping Computer, which covers information security and technology news.

Advertisement

“We believe these files are related to an incident at a third-party vendor and are unrelated to our security incident in September,” said Carissa Simons, the Uber spokesperson. “Based on our initial review of the information available, the code is not owned by Uber; however, we are continuing to look into this matter.”

Advertisement

Teqtivity said in a statement it doesn't collect or store sensitive information such as bank account details or government identification numbers. The exposed data includes device information such as serial number, make and model as well as user information such as full name, work email address and location.

Teqtivity said customer data was compromised due to unauthorized access to its systems by a malicious third party. The hacker was was able to gain access to the Teqtivity AWS backup server that houses the company's code and data files related to its customers, according to the company.

Advertisement

Teqtivity has notified law enforcement officials and hired a forensics firm to investigate all logs and server configuration.

The leak is the latest breach to affect Uber. Uber said the attackers (or attacker) responsible for a September breach were affiliated with the notorious extortion group called Lapsus$ and had likely infected a contractor's personal device with malware and then bought that person's password on the dark web.

Advertisement

In that instance, the intruders were able to get into several employee accounts and had security permissions for Uber's G-Suite and Slack, among other internal tools.

In October, former Uber security chief Joe Sullivan was found guilty of hiding a massive 2016 data breach from federal regulators

© 2022 Bloomberg LP


The Chromecast with Google TV that runs on Android TV is here. When will Google learn how to name products? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Uber, Leak, Hack, Teqtivity
Advertisement

Related Stories

Popular Mobile Brands
  1. One Piece: Into the Grand Line OTT Release Date Revealed: What You Need to Know
  1. Hubble Observes Massive Stellar Eruption from EK Draconis, Hinting at Life’s Origins
  2. Scientists Detect Hidden Magnetic Waves That Could Explain the Sun’s Mysterious Heat
  3. Scientists Propose Space-Based Carbon-Neutral Data Centres for Sustainable Computing
  4. SpaceX Falcon Heavy Launch of Private Griffin Moon Lander Pushed to 2026 Amid Testing Phase
  5. Russian Cosmonauts Complete Second Spacewalk to Install New Experiments on ISS Exterior
  6. Tsinghua Scientists Create Light-Powered AI Chip Running at 12.5 GHz
  7. LIGO Detect Possible Second-Generation Black Holes with Extreme Spins
  8. Scientists Stunned as Earth’s Magnetosphere Shows Reversed Electric Charge Patterns
  9. One Piece: Into the Grand Line OTT Release Date Revealed: What You Need to Know
  10. Ballad of a Small Player Streaming Online: Know Where to Watch This Collin Farrell Starrer Movie
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.