logo

Uber Network Compromised by Hackers

ID: 5cc6cd6f-e183-548d-a493-56ca24050e14

STIX ID: report--5cc6cd6f-e183-548d-a493-56ca24050e14

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-05-21

Date Updated: 2026-07-16

...
...

**Executive summary:** On 15 September 2022 CRIL reported that threat actor "Tea Pot" compromised Uber by targeting an employee (via social engineering and MFA interception) to gain VPN and internal access; public screenshots allegedly show access to Slack, HackerOne, internal finance and intranet portals, Active Directory, GCP/AWS consoles, and SentinelOne, and CRIL maps the activity to MITRE ATT&CK techniques (phishing, MFA interception, valid accounts, remote service exploitation, cloud discovery, and adversary-in-the-middle).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.