We Will Ensure What Happened with Uber in 2022 Won't Happen to You
Arjun4 min read
PRIVILEGED ACCESS-SECURITY#uber#pam-security#lapsus

We Will Ensure What Happened with Uber in 2022 Won't Happen to You

Uber's 2022 breach via hardcoded PAM credentials resulted in total infrastructure takeover. Learn how Mine2's honeytokens and breach traps can detect secrets sprawl and prevent privileged access compromise.

Share:

In September 2022, Uber suffered a total internal takeover. A single compromised contractor account—bought on the dark web—led to domain admin access across AWS, GCP, VMware, Slack, SentinelOne, and Uber's HackerOne console. The linchpin? A hardcoded admin credential in a PowerShell script that unlocked Thycotic, Uber's Privileged Access Management (PAM) system. From there, the attacker, affiliated with LAPSUS$, held the master key to every door.

Uber

This wasn't a zero-day or a clever exploit. It was a secrets sprawl disaster—three breaches in eight years, all tied to leaked credentials. Uber paid millions in recovery, lost trust, and still can't be sure the attacker left no backdoors.

It was also preventable. With the right detection layer, it won't happen to you.

The Uber Breach: A Masterclass in Secrets Failure

Here's how it unfolded:

  1. Social engineering → VPN access An external contractor fell for a phishing campaign. Their credentials were sold on a criminal marketplace.

  2. PowerShell script → PAM admin Inside Uber's network, the attacker found a script with hardcoded domain admin credentials for Thycotic. One line of code equaled full PAM takeover.

  3. PAM = keys to the kingdom Thycotic stored credentials for AWS, GCP, GSuite, Slack, SentinelOne, and more. The attacker enumerated and extracted them at will.

  4. Lateral movement and persistence

    • Reconfigured AWS IAM roles
    • Accessed VMware vSphere hypervisors
    • Disabled alerts in SentinelOne
    • Posted taunts in Slack and HackerOne

"Finding admin credentials to a PAM system is like finding a master key to every room and alarm system, in every building, in every country." — Mackenzie Jackson, GitGuardian

Uber's 2014 and 2016 breaches? Same root cause: leaked secrets in public repos and weak password hygiene. History repeated, only louder.

Why Traditional Tools Failed Uber

I build detections for a living, and this chain is humbling precisely because nothing "fired."

  • Secrets scanners? Too late—the credentials were already in production.
  • MFA? Bypassed with stolen session tokens.
  • SIEM? No alert on a "legitimate" admin login from a new IP.
  • PAM? Compromised because it was the single source of truth.

The attacker never had to exploit a vulnerability. They just used what was already there. That's the recurring shape of these incidents, the same one behind the BeyondTrust PAM breach and the slow service-account lateral movement we broke down separately.

Deception: Your Early-Warning PAM Shield

This is where cyber deception—specifically Mine2.io—changes the math. Instead of hoping secrets stay hidden, you turn the attacker's own curiosity into a trigger.

How Mine2 Would Have Stopped Uber Cold

Attack Phase Mine2 Deception Countermeasure
Phished contractor login Canary tokens in VPN logs – Fake session IDs trigger silent alerts on first use.
PowerShell script discovery Honeytoken credentials – Bogus Thycotic admin creds planted in scripts. Any use → instant detection.
PAM access attempt Decoy PAM vault – A fully functional fake Thycotic instance. The attacker logs in, extracts fake keys, wastes hours.
Lateral movement Breach traps – Decoy AWS consoles, Slack bots, and SentinelOne dashboards divert and log every move.

The payoff is a clean signal: zero false positives, real-time alerts, automated containment. Decoys only ever get touched by someone who shouldn't be there.

Even if the real Thycotic had been compromised, the first touch of a honeytoken would have fired off session termination, credential rotation, and the IR playbook—all before the attacker reached AWS or Slack. The same secrets-sprawl problem turned a single repo into a catastrophe for Red Hat's consulting customers, and it's why a hardcoded key sat undetected in Toyota's public GitHub repo for five years.

Build Your "Uber-Proof" Defense Today

You don't need to rip out your PAM, MFA, or EDR. You layer deception on top of them.

Immediate moves with Mine2.io:

  1. Seed honeytokens in scripts and configs – Five minutes to plant fake PAM, AWS, and GCP keys.
  2. Deploy decoy admin accounts – Lure attackers into monitored traps.
  3. Monitor with zero noise – Only malicious behavior trips an alert.
  4. Integrate with SOAR – Auto-kill sessions the moment deception triggers.

Uber's breach wasn't bad luck. It was predictable exposure without early detection. See how the seeding works on the Mine2 product page.

With Mine2.io active, no attacker touches a real secret without you knowing—on day one. Don't wait for your own "Uber moment." Book a walkthrough and let's wire the traps together.

M2

Arjun

Lead Detection Engineer, Mine2

Arjun builds detection logic at Mine2, focusing on the blind spots EDR and SIEM leave behind and how honeytokens close them.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.