MFA Fatigue, or How Uber Got Owned By a Text Message

MFA Fatigue, or How Uber Got Owned By a Text Message

Tech News data breach mfa security uber

I was halfway through setting up a new phone stand on my desk last night (a whole saga involving three different mounting arms and a dremel I genuinely do not know how to use) when the Uber breach news started showing up in my feeds. Out of everything happening in tech this week, this is the story that actually made me go check my own account settings afterward.

Quick recap for anyone who missed it: sometime Thursday night an 18-year-old, allegedly loosely tied to the Lapsus$ crowd though who really knows at this point, got into Uber's internal systems. Not through some exotic zero-day. He bought an employee's password off the dark web, probably from one of the endless credential dumps that circulate after basically any breach anywhere, and then just texted the guy. Pretended to be IT support over WhatsApp, told him the MFA push notifications he was getting were normal and expected, and kept it up until the employee got annoyed enough to just tap approve.

That's it. That's the whole hack. No malware, no clever exploit chain. Just someone getting tired of their phone buzzing.

From there the attacker reportedly found a PowerShell script sitting on a network share with admin credentials hardcoded right into it, for Thycotic, which is a privileged access management tool, which is a very funny thing to find hardcoded credentials lying around for. From there he basically walked into everything: AWS, GCP, the internal Slack, Uber's own bug bounty reports (so he could see which known vulnerabilities hadn't been patched yet), SentinelOne dashboards, the works. Then posted a message announcing himself in the company Slack, and apparently renamed a few internal tools to include some choice NSFW commentary, because of course he did.

Uber's line so far is that no sensitive rider data, trip history, that sort of thing, got touched, and I've got no particular reason to doubt the "we caught it before real damage" part. But that's not the part that's stuck with me since yesterday.

The part that's stuck with me is the push notification piece, because I deal with a version of this at my own job constantly. We switched to an authenticator app a few months back that sends a push instead of making you type in a rotating code, and I cannot tell you how many times I've tapped approve on one of those half asleep, phone buzzing at 7:40 in the morning while I'm still patting the nightstand for my glasses, brain not even registering what I just clicked. It's built to be frictionless and that is precisely the problem with it. A six-digit code forces you to stop and actually look at what's asking and why. A push notification just wants a thumb, and thumbs are lazy.

I'm not saying MFA is bad. Obviously it beats a password alone, which at this point is basically a decorative object. But push-based approval is the laziest possible implementation of it, and this Uber situation is exactly what happens when "laziest possible" runs into a patient teenager with a WhatsApp account and forty-five minutes to kill. Give me a rotating code. Give me a hardware key. Give me anything that requires me to read a screen before I hit yes.

Completely separate topic, my group chat has been nothing but iPhone 14 Pro screenshots since yesterday, everyone showing off the new Dynamic Island thing where the camera cutout turns into a little pill that expands for notifications and Live Activities. It's a genuinely clever piece of software design, turning a hardware limitation most people hated into something people are now excited about. I've still got a 13 that works perfectly fine though, and I'm not paying $999 just to get a nicer-looking cutout, not this year anyway. Ask me again in eleven months once the battery's degraded and I've conveniently forgotten I said that.

Go check whether your own accounts use push-approval MFA, and if you can switch to a code-based option, do it. Screenshots of the actual Slack messages from inside Uber were floating around online within a day of this breaking, and honestly that's the detail that unsettled me most, how casual and unhurried the whole thing reads once you get past the "an 18 year old did this" headline.