logo

Uber Cybersecurity Incident: Which Logs Do IR Teams Need to Focus On?

ID: 25ed827f-2d63-540b-a73a-9f1755a20446

STIX ID: report--25ed827f-2d63-540b-a73a-9f1755a20446

Feed Name: Mitiga

Threat Score
85/100

Date Published: 2026-07-16

Date Updated: 2026-08-03

...
...

On September 16 Uber disclosed a major compromise where an attacker leveraged phishing to obtain admin credentials and pivoted across multiple services (Thycotic PAM, AWS, Google Workspace, HackerOne, Slack). The report enumerates the relevant audit and activity logs investigators should collect from each platform (Thycotic audit reports, AWS CloudTrail, Google Reports API, HackerOne and Slack audit logs) to trace actions, detect anomalous privileged behavior, and recommends a holistic breach readiness approach including forensic data lakes and SaaS/cloud-focused IR partnerships.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.