IOTW: Hacker allegedly hits both Uber and Rockstar

A hacker has claimed they are responsible for hacking into both companies’ servers

Add bookmark
Hacker allegedly hits both Uber and Rockstar

It has been alleged that the hacker who gained unauthorized access to rideshare service Uber’s servers was also responsible for a similar hack into the systems of Rockstar Games, developer of the Grand Theft Auto (GTA) game series.

The hack into Rockstar Games was discovered on September 19, 2022 after a user called teapotuberhacker posted on Grand Theft Auto game series fan site GTAForums:

“Here are 90 footage/clips from GTA 6. It’s possible I could leak more data soon, GTA 5 and 6 source code and assets, GTA 6 testing build.”

In the post’s comments, the hacker claimed they had “downloaded [the gameplay videos] from Slack” via hacking into channel used for communicating about the game.

Teapotuberhacker also alleged tried to “negotiate an agreement” with Rockstar Games regarding the return of the source code and assets. After Rockstar Games did not communicate with them, however, they announced that they would be selling the GTA 6 source code and documents they had downloaded.

Bloomberg journalist Jason Schreier initially confirmed the hack in a tweet, saying he had “confirmed with Rockstar sources that this weekend’s massive Grand Theft Auto VI leak is indeed real”. Rockstar Games later made a statement via Twitter.

It said that Rockstar had suffered a “network intrusion” which had allowed an unauthorized third party to "illegally access and download confidential information form [its] systems”, including the leaked GTA 6 footage.  

Rockstar confirmed that they will continue to work on the game and GTA’s publisher Take Two has been issuing takedown notices to get clips of the game removed from social media.

What happened in the Uber hack?

The hack into Uber’s database took place on September 15, 2022 and involved a compromised Uber EXT account that led to internal servers being accessed. 

In a statement, the rideshare service company said the contractor’s password was accessed as their personal device became infected with malware and sold on the dark web.  

When attempting to log in using the stolen credentials, the hacker employed a technique called Multi-Factor Authentication (MFA) fatigue, wherein they spammed the contractor with two-factor approval requests. While this initially blocked access, the contractor eventually accepted one of the requests, allowing the hacker access to Uber’s systems.

According to Uber, the hacker then “accessed several other employee accounts which ultimately gave the attacker elevated permissions to a number of tools, including G-Suite and Slack”, then “posted a message to a company-wide Slack channel...and reconfigured Uber’s OpenDNS to display a graphic image to employees on some internal sites”.

Uber responded to the hack by identifying the accounts that were compromised and blocking their access to Uber’s internal network. It then disabled and reset access to affected internal tools, locked down its code database to prevent any changes and added additional monitoring to its internal environment.

An investigation into the hack is still ongoing, however, Uber noted that it had not seen any evidence that the hacker had “accessed the production...systems that power [its] apps”. This means the hacker most likely did not retrieved any customer personal information or made any changes to its codebase.  

Additionally, while the hacker was able to access Uber’s HackerOne database, which the company uses to report any vulnerabilities, “any bug reports the attacker was able to access have been remediated”. 

The hack was linked to the Lapsus$ hacking group by Uber, it “typically uses similar techniques to target technology companies”. The group has been responsible for a number of hacks against technology companies in 2022 including Samsung, Microsoft, RobinHood, MailChimp and Okta. Uber also suggested that Lapsus$ was responsible for the hack into Rockstar Games.

What are Lapsus$?

Lapsus$ are a malicious hacking group that has been classified as DEV-0537 by Microsoft. The group is known for using social engineering attacks to gain access to employee credentials at the companies they target.  

According to Microsoft, Lapsus$ frequently “announc[e] their attacks on social media or advertis[e] their intent to buy credentials from employees of target organizations”.

Lapsus$ have been linked to a number of high-profile hacking cases, including one in March of this year where the group hacked both Okta and Microsoft within a week. In both cases, a single employee’s account was compromised, leading to access to both companies’ internal servers. 


Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":0,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"62e163ec41618908fd2621ca","name":"IOTW: Uber reaches settlement following cover up of data breach","description":"The ride-sharing app has admitted to covering up a major data breach in 2016 that affected 57 million users","file":null,"url":"\/attacks\/news\/iotw-uber-reaches-settlement-following-coverup-of-data-breach"},{"id":"61978f543120251a2c3fa927","name":"IOTW: Hacker highlights FBI vulnerabilities in email hoax","description":"Hack of FBI operated server sees fake security alerts sent from FBI email address","file":null,"url":"\/attacks\/articles\/iotw-hacker-highlights-fbi-vulnerabilities-in-email-hoax"},{"id":"624efaad3120251d580229a8","name":"IOTW: Social engineering attack sees Mailchimp hacked","description":"Mailchimp employee account compromised by a social engineering attack","file":null,"url":"\/attacks\/news\/iotw-social-engineering-attack-sees-mailchimp-hacked"},{"id":"62e3beef6ceab07f824156af","name":"What is social engineering?","description":"A guide to social engineering and how to guard against this attack vector","file":null,"url":"\/threat-defense\/articles\/what-is-social-engineering"},{"id":"62f4e94acbeb1317b057d394","name":"IOTW: Twilio suffers data breach following phishing attack","description":"The company\u2019s employees were directly targeted by a phishing attack disguised to look like it came from Twilio\u2019s IT department","file":null,"url":"\/attacks\/news\/iotw-twilio-suffers-data-breach-following-phishing-attack"}],"featured_content_portal_embedded":null}" >