Uber hit by new data breach — what you need to know

Uber app open a phone next to a car
(Image credit: Photo Illustration by Omar Marques/SOPA Images/LightRocket via Getty Images)

The popular ride-sharing platform Uber has suffered yet another data breach after a cybercriminal began posting sensitive company information stolen from a third-party vendor online.

As reported by BleepingComputer, the cybercriminal made a number of posts on a popular hacking forum under the name ‘UberLeaks’ early on Saturday morning. These posts allegedly contained data stolen from both Uber and Uber Eats.

This leaked data includes a number archives which UberLeaks claims are source code from mobile device management (MDM) platforms used by both companies as well as third-party vendors. Threeseparate topics were made for Uber MDM, Uber Eats MDM and the Teqtivity MDM platform which are used by Uber.

Surprisingly, each of these topics refer to a member of the infamous Lapsus$ hacking group. Besides being responsible for high-profile attacks on Nvidia, Samsung, Ubisoft and even Microsoft, the group also launched a cyberattack on Uber this September where it gained access to the company’s internal network as well as its Slack server.

UberLeaks

An open lock depicting a data breach

(Image credit: Shutterstock)

According to people familiar with the matter that spoke with BleepingComputer, this newly leaked data contains source code, IT asset management reports, data destruction reports, Windows domain login names and email addresses as well as other corporate information.

For instance, one of the documents seen by the news outlet included the email addresses and Windows Active Directory information for more than 77,000 Uber employees. While it initially appeared like this data was stolen during the September attack on Uber, the company provided further insight into the matter in a statement to RestorePrivacy who broke the story, saying:

“We believe these files are related to an incident at a third-party vendor and are unrelated to our security incident in September. Based on our initial review of the information available, the code is not owned by Uber; however, we are continuing to look into this matter.”

Should you be worried about the latest Uber data breach?

News of a data breach at a large company – especially one you use personally – is normally cause for concern. Was my credit card number leaked? Do I need to change my password? Could my identity be stolen?

In this case though, it looks like only Uber’s internal corporate information was leaked online, so ride-share customers aren’t affected. Uber employees on the other hand need to be careful as security researchers who examined the data told BleepingComputer that there is enough detailed information to carry out targeted phishing attacks against them.

If you’re still worried though, you can always change your Uber password for added peace of mind. At the same time, you might want to consider signing up for one of the best identity theft protection services as they can help you deal with fraud and getting your identity back should it be stolen.

Anthony Spadafora
Managing Editor Security and Home Office

Anthony Spadafora is the managing editor for security and home office furniture at Tom’s Guide where he covers everything from data breaches to password managers and the best way to cover your whole home or business with Wi-Fi. He also reviews standing desks, office chairs and other home office accessories with a penchant for building desk setups. Before joining the team, Anthony wrote for ITProPortal while living in Korea and later for TechRadar Pro after moving back to the US. Based in Houston, Texas, when he’s not writing Anthony can be found tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Amazon GrubHub delivery
Grub Hub data breach exposed contact and payment information of diners, merchants and drivers — here’s what we know
Discord on a phone and a laptop
Reported Discord data leak disputed by third-party service RestoreCard
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
Surfshark graphic of 2024 data breaches
Nearly 700 million American records were leaked in 2024
An open lock depicting a data breach
12 million hit in Zacks Investment data breach — how to protect yourself now
An open lock depicting a data breach
The top 10 data breaches of 2024
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now