Platform
Solutions
Resources
Company
Platform
Solutions
Resources
Company

Nick Morgan
∙
Uber Hack & MFA Fatigue Explained


Nick Morgan
∙
Uber Hack & MFA Fatigue Explained


Nick Morgan
∙
Uber Hack & MFA Fatigue Explained

The 2022 Uber breach wasn't a sophisticated technical exploit. It was an 18-year-old attacker who bought a contractor's stolen password on the dark web, then wore down the contractor's patience with repeated MFA push notifications until one got approved by mistake. Within hours, Uber confirmed the attacker had reached internal tools including Slack, AWS, and Google Workspace.
The breach matters less for its scale than for what it proves: multi-factor authentication, the control most companies treat as their strongest safeguard, can be defeated with nothing more than persistence and a fake IT text message.
How the Attack Actually Worked
On September 15, Uber employees saw this message posted to the company's internal Slack:
"Hi @here I announce I am a hacker and Uber has suffered a data breach."
According to Wired's reporting at the time, the attacker had "deeply and thoroughly compromised" Uber's internal systems, limited only by time, not by access. Breaching a multi-billion dollar company sounds like it demands serious technical skill. It didn't, here.
Step | What happened |
|---|---|
1. Credential theft | The attacker acquired a contractor's username and password, reportedly purchased after the contractor's device was infected with malware |
2. MFA blocks initial access | Logging in triggered a multi-factor approval request on the employee's device, which initially stopped the attacker cold |
3. MFA bombing | The attacker sent repeated authentication requests in quick succession, hoping to wear the employee down |
4. Social engineering | The attacker then texted the employee posing as Uber IT support, asking them to approve the request to make the notifications stop |
5. Access granted | The employee complied. That single approval was enough to let the attacker in |
From that point, a routine act of social engineering had bypassed defenses Uber had invested heavily in.
"Weaknesses in a company's cybersecurity can come from a multitude of places, logins, backdoors, and more," said Gene Shablygin, CEO, WWPass. "For a company that invests in cybersecurity as much as Uber does, it's jarring to see such a simple exploit used to give a threat actor so much access."
Why MFA Wasn't Enough
Multi-factor authentication was supposed to be the failsafe here, and for a while, it was: it did block the attacker from getting in on credentials alone. But deception, the same trick that lets scammers harvest passwords and personal information every day, was enough to get around it.
MFA can take the form of a randomized code, an approval button, or a text message, and its ubiquity has created a false sense of security. It's often treated as a foolproof defense against compromised credentials. It isn't, and it was never designed to stop social engineering in the first place.
"Just as social engineering can siphon your logins through a fabricated email or suspicious text message, it can just as easily circumvent multi-factor authentication," said Shablygin. "While another hoop for a hacker to jump through, the existence of multi-factor authentication doesn't make a login invincible."
Uber later confirmed the attacker didn't access user data or meaningfully disrupt operations, but the company still had real work ahead reviewing its cybersecurity posture.
What Actually Prevents This
The lesson isn't "use stronger MFA." Traditional MFA, push notifications, SMS codes, one-time passcodes, still depends on a human making the right call under pressure, and this attack is a case study in how reliably that assumption breaks. The fix that holds up is phishing-resistant MFA: authentication that's cryptographically bound to the legitimate origin, so there's no push notification to bomb and no approval prompt a fake IT rep can talk someone into tapping.
To prevent breaches like this, enterprises should focus less on hardening traditional username-and-password logins and more on removing that layer entirely.
"Traditional username and password logins, whether with or without multi-factor authentication, will always be susceptible to some of the most common types of hacking, including social engineering," said Shablygin. "Instead of attempting to continually harden these traditional logins, enterprises should instead scrap them altogether and try a new approach."
Login options that skip traditional credentials entirely are becoming more common, in part because there's nothing left for a threat actor to steal or trick someone into approving. WWPass's usernameless and passwordless login removes credentials as an exploitable variable in the first place, which is particularly relevant for privileged and administrative access, the exact tier of account this breach escalated into once the attacker was inside.
"At WWPass, we want to help companies and everyday users alike understand that a more secure approach to traditional logins exists," said Shablygin. "That alternative doesn't have to compromise security or convenience. In fact, WWPass is looking to set a new standard, one where cybersecurity failures like Uber's recent breach are a thing of the past."
FAQ
What is MFA fatigue?
MFA fatigue, also called MFA bombing or push bombing, is a social engineering technique where an attacker repeatedly sends authentication approval requests to a target's device, hoping the person eventually approves one out of frustration or confusion, often with a follow-up message posing as IT support to push them toward approving.
Did multi-factor authentication fail in the Uber breach?
Not exactly, it did its job initially and blocked the attacker's login attempts. What failed was the assumption that a human under repeated pressure will always make the right call. The attacker didn't break the MFA, they talked the employee into approving it.
How is phishing-resistant MFA different from standard MFA?
Standard MFA (SMS codes, push notifications, one-time passcodes) can be relayed, spoofed, or approved under social pressure, as this breach demonstrated. Phishing-resistant MFA cryptographically binds authentication to the legitimate origin, so there's no approval prompt to bomb and no code to phish.
Could removing passwords entirely have prevented this attack?
It would have removed the initial entry point. The attacker's first step was a stolen username and password bought on the dark web. Without a static credential to steal in the first place, that step, and the MFA-fatigue attack that followed it, has nothing to build on.
The Bottom Line
Uber's breach wasn't a failure of effort or investment, it was a failure of architecture. MFA added a hoop for the attacker to jump through, not a wall. As long as authentication depends on a human approving a prompt, it depends on that human never having a bad day, a five-alarm shift, or a convincing text message. Removing the credential and the approval prompt removes the opening this entire attack relied on.
The 2022 Uber breach wasn't a sophisticated technical exploit. It was an 18-year-old attacker who bought a contractor's stolen password on the dark web, then wore down the contractor's patience with repeated MFA push notifications until one got approved by mistake. Within hours, Uber confirmed the attacker had reached internal tools including Slack, AWS, and Google Workspace.
The breach matters less for its scale than for what it proves: multi-factor authentication, the control most companies treat as their strongest safeguard, can be defeated with nothing more than persistence and a fake IT text message.
How the Attack Actually Worked
On September 15, Uber employees saw this message posted to the company's internal Slack:
"Hi @here I announce I am a hacker and Uber has suffered a data breach."
According to Wired's reporting at the time, the attacker had "deeply and thoroughly compromised" Uber's internal systems, limited only by time, not by access. Breaching a multi-billion dollar company sounds like it demands serious technical skill. It didn't, here.
Step | What happened |
|---|---|
1. Credential theft | The attacker acquired a contractor's username and password, reportedly purchased after the contractor's device was infected with malware |
2. MFA blocks initial access | Logging in triggered a multi-factor approval request on the employee's device, which initially stopped the attacker cold |
3. MFA bombing | The attacker sent repeated authentication requests in quick succession, hoping to wear the employee down |
4. Social engineering | The attacker then texted the employee posing as Uber IT support, asking them to approve the request to make the notifications stop |
5. Access granted | The employee complied. That single approval was enough to let the attacker in |
From that point, a routine act of social engineering had bypassed defenses Uber had invested heavily in.
"Weaknesses in a company's cybersecurity can come from a multitude of places, logins, backdoors, and more," said Gene Shablygin, CEO, WWPass. "For a company that invests in cybersecurity as much as Uber does, it's jarring to see such a simple exploit used to give a threat actor so much access."
Why MFA Wasn't Enough
Multi-factor authentication was supposed to be the failsafe here, and for a while, it was: it did block the attacker from getting in on credentials alone. But deception, the same trick that lets scammers harvest passwords and personal information every day, was enough to get around it.
MFA can take the form of a randomized code, an approval button, or a text message, and its ubiquity has created a false sense of security. It's often treated as a foolproof defense against compromised credentials. It isn't, and it was never designed to stop social engineering in the first place.
"Just as social engineering can siphon your logins through a fabricated email or suspicious text message, it can just as easily circumvent multi-factor authentication," said Shablygin. "While another hoop for a hacker to jump through, the existence of multi-factor authentication doesn't make a login invincible."
Uber later confirmed the attacker didn't access user data or meaningfully disrupt operations, but the company still had real work ahead reviewing its cybersecurity posture.
What Actually Prevents This
The lesson isn't "use stronger MFA." Traditional MFA, push notifications, SMS codes, one-time passcodes, still depends on a human making the right call under pressure, and this attack is a case study in how reliably that assumption breaks. The fix that holds up is phishing-resistant MFA: authentication that's cryptographically bound to the legitimate origin, so there's no push notification to bomb and no approval prompt a fake IT rep can talk someone into tapping.
To prevent breaches like this, enterprises should focus less on hardening traditional username-and-password logins and more on removing that layer entirely.
"Traditional username and password logins, whether with or without multi-factor authentication, will always be susceptible to some of the most common types of hacking, including social engineering," said Shablygin. "Instead of attempting to continually harden these traditional logins, enterprises should instead scrap them altogether and try a new approach."
Login options that skip traditional credentials entirely are becoming more common, in part because there's nothing left for a threat actor to steal or trick someone into approving. WWPass's usernameless and passwordless login removes credentials as an exploitable variable in the first place, which is particularly relevant for privileged and administrative access, the exact tier of account this breach escalated into once the attacker was inside.
"At WWPass, we want to help companies and everyday users alike understand that a more secure approach to traditional logins exists," said Shablygin. "That alternative doesn't have to compromise security or convenience. In fact, WWPass is looking to set a new standard, one where cybersecurity failures like Uber's recent breach are a thing of the past."
FAQ
What is MFA fatigue?
MFA fatigue, also called MFA bombing or push bombing, is a social engineering technique where an attacker repeatedly sends authentication approval requests to a target's device, hoping the person eventually approves one out of frustration or confusion, often with a follow-up message posing as IT support to push them toward approving.
Did multi-factor authentication fail in the Uber breach?
Not exactly, it did its job initially and blocked the attacker's login attempts. What failed was the assumption that a human under repeated pressure will always make the right call. The attacker didn't break the MFA, they talked the employee into approving it.
How is phishing-resistant MFA different from standard MFA?
Standard MFA (SMS codes, push notifications, one-time passcodes) can be relayed, spoofed, or approved under social pressure, as this breach demonstrated. Phishing-resistant MFA cryptographically binds authentication to the legitimate origin, so there's no approval prompt to bomb and no code to phish.
Could removing passwords entirely have prevented this attack?
It would have removed the initial entry point. The attacker's first step was a stolen username and password bought on the dark web. Without a static credential to steal in the first place, that step, and the MFA-fatigue attack that followed it, has nothing to build on.
The Bottom Line
Uber's breach wasn't a failure of effort or investment, it was a failure of architecture. MFA added a hoop for the attacker to jump through, not a wall. As long as authentication depends on a human approving a prompt, it depends on that human never having a bad day, a five-alarm shift, or a convincing text message. Removing the credential and the approval prompt removes the opening this entire attack relied on.
The 2022 Uber breach wasn't a sophisticated technical exploit. It was an 18-year-old attacker who bought a contractor's stolen password on the dark web, then wore down the contractor's patience with repeated MFA push notifications until one got approved by mistake. Within hours, Uber confirmed the attacker had reached internal tools including Slack, AWS, and Google Workspace.
The breach matters less for its scale than for what it proves: multi-factor authentication, the control most companies treat as their strongest safeguard, can be defeated with nothing more than persistence and a fake IT text message.
How the Attack Actually Worked
On September 15, Uber employees saw this message posted to the company's internal Slack:
"Hi @here I announce I am a hacker and Uber has suffered a data breach."
According to Wired's reporting at the time, the attacker had "deeply and thoroughly compromised" Uber's internal systems, limited only by time, not by access. Breaching a multi-billion dollar company sounds like it demands serious technical skill. It didn't, here.
Step | What happened |
|---|---|
1. Credential theft | The attacker acquired a contractor's username and password, reportedly purchased after the contractor's device was infected with malware |
2. MFA blocks initial access | Logging in triggered a multi-factor approval request on the employee's device, which initially stopped the attacker cold |
3. MFA bombing | The attacker sent repeated authentication requests in quick succession, hoping to wear the employee down |
4. Social engineering | The attacker then texted the employee posing as Uber IT support, asking them to approve the request to make the notifications stop |
5. Access granted | The employee complied. That single approval was enough to let the attacker in |
From that point, a routine act of social engineering had bypassed defenses Uber had invested heavily in.
"Weaknesses in a company's cybersecurity can come from a multitude of places, logins, backdoors, and more," said Gene Shablygin, CEO, WWPass. "For a company that invests in cybersecurity as much as Uber does, it's jarring to see such a simple exploit used to give a threat actor so much access."
Why MFA Wasn't Enough
Multi-factor authentication was supposed to be the failsafe here, and for a while, it was: it did block the attacker from getting in on credentials alone. But deception, the same trick that lets scammers harvest passwords and personal information every day, was enough to get around it.
MFA can take the form of a randomized code, an approval button, or a text message, and its ubiquity has created a false sense of security. It's often treated as a foolproof defense against compromised credentials. It isn't, and it was never designed to stop social engineering in the first place.
"Just as social engineering can siphon your logins through a fabricated email or suspicious text message, it can just as easily circumvent multi-factor authentication," said Shablygin. "While another hoop for a hacker to jump through, the existence of multi-factor authentication doesn't make a login invincible."
Uber later confirmed the attacker didn't access user data or meaningfully disrupt operations, but the company still had real work ahead reviewing its cybersecurity posture.
What Actually Prevents This
The lesson isn't "use stronger MFA." Traditional MFA, push notifications, SMS codes, one-time passcodes, still depends on a human making the right call under pressure, and this attack is a case study in how reliably that assumption breaks. The fix that holds up is phishing-resistant MFA: authentication that's cryptographically bound to the legitimate origin, so there's no push notification to bomb and no approval prompt a fake IT rep can talk someone into tapping.
To prevent breaches like this, enterprises should focus less on hardening traditional username-and-password logins and more on removing that layer entirely.
"Traditional username and password logins, whether with or without multi-factor authentication, will always be susceptible to some of the most common types of hacking, including social engineering," said Shablygin. "Instead of attempting to continually harden these traditional logins, enterprises should instead scrap them altogether and try a new approach."
Login options that skip traditional credentials entirely are becoming more common, in part because there's nothing left for a threat actor to steal or trick someone into approving. WWPass's usernameless and passwordless login removes credentials as an exploitable variable in the first place, which is particularly relevant for privileged and administrative access, the exact tier of account this breach escalated into once the attacker was inside.
"At WWPass, we want to help companies and everyday users alike understand that a more secure approach to traditional logins exists," said Shablygin. "That alternative doesn't have to compromise security or convenience. In fact, WWPass is looking to set a new standard, one where cybersecurity failures like Uber's recent breach are a thing of the past."
FAQ
What is MFA fatigue?
MFA fatigue, also called MFA bombing or push bombing, is a social engineering technique where an attacker repeatedly sends authentication approval requests to a target's device, hoping the person eventually approves one out of frustration or confusion, often with a follow-up message posing as IT support to push them toward approving.
Did multi-factor authentication fail in the Uber breach?
Not exactly, it did its job initially and blocked the attacker's login attempts. What failed was the assumption that a human under repeated pressure will always make the right call. The attacker didn't break the MFA, they talked the employee into approving it.
How is phishing-resistant MFA different from standard MFA?
Standard MFA (SMS codes, push notifications, one-time passcodes) can be relayed, spoofed, or approved under social pressure, as this breach demonstrated. Phishing-resistant MFA cryptographically binds authentication to the legitimate origin, so there's no approval prompt to bomb and no code to phish.
Could removing passwords entirely have prevented this attack?
It would have removed the initial entry point. The attacker's first step was a stolen username and password bought on the dark web. Without a static credential to steal in the first place, that step, and the MFA-fatigue attack that followed it, has nothing to build on.
The Bottom Line
Uber's breach wasn't a failure of effort or investment, it was a failure of architecture. MFA added a hoop for the attacker to jump through, not a wall. As long as authentication depends on a human approving a prompt, it depends on that human never having a bad day, a five-alarm shift, or a convincing text message. Removing the credential and the approval prompt removes the opening this entire attack relied on.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.
