Skip to main content

Stolen Uber accounts on sale for $1 each

uber nyc scheduled rides app portland
Image used with permission by copyright holder
According to a Motherboard report, stolen Uber user accounts are being traded in the shadier corners of the Web, changing hands for as little as $1 each. Exactly where these account credentials have been obtained isn’t clear, and Uber itself has denied any breach of its systems.

It seems that these accounts have been obtained without authorization and without Uber or users knowing. Buy one of these sets of login details and you can then take a taxi ride and charge it to someone else’s tab. Although the actual credit card data is not included in the information for sale, each Uber account is linked to a card for instant billing.

“We investigated and found no evidence of a breach,” said Uber in response to Motherboard’s article. “Attempting to fraudulently access or sell accounts is illegal and we notified the authorities about this report. This is a good opportunity to remind people to use strong and unique usernames and passwords and to avoid reusing the same credentials across multiple sites and services.”

If you use your Uber password elsewhere, now might be a good time to change it. Trip history, phone numbers, and email addresses could also be exposed through the unauthorized use of someone else’s details, and based on Motherboard’s investigating they seem to be genuine accounts. The sellers are claiming to have thousands of accounts to distribute.

It’s not been the easiest year for Uber so far. Back in February, the company reported that details for 50,000 of its drivers could have leaked out into the public domain, while the firm also had to take extra steps to ensure passenger and driver safety on the roads. Only a few days ago the service was banned in Germany over a row about driver permits.

Editors' Recommendations

David Nield
Dave is a freelance journalist from Manchester in the north-west of England. He's been writing about technology since the…
The Uber hack is an outrageous tale of a teen hacking for fun
An Uber cab

Uber suffered a serious breach of its system earlier this month, allowing the bad actor to wreak all sorts of havoc — from spamming the employee Slack chats with explicit imagery to defacing the internal websites and stealing sensitive media. The ride-sharing company has now released an updated statement, putting the blame on the infamous Lapsus$ hacking group.

The attack, and the subsequent announcement, were so brazen that some employees took it as a joke from one of their colleagues and responded to the hacker's message with light-hearted emojis. The hacker revealed to The New York Times that he was an 18-year-old person. To further rub salt into Uber’s wounds, the cybercriminal told The Washington Post that he breached the company’s systems for fun and might leak the source code in the coming months.

Read more
Uber says it’s investigating ‘cybersecurity incident’
An Uber App on a smartphone.

Computer systems belonging to ridesharing giant Uber appear to have been targeted by hackers in what could be a serious security breach. The company reported on Thursday evening that it had contacted law enforcement after learning of what it described as a “cybersecurity incident.”

In a tweet posted at about 9:30 p.m. ET, Uber said: “We are currently responding to a cybersecurity incident. We are in touch with law enforcement and will post additional updates here as they become available.”

Read more
Personal data of 69 million Neopets users is now up for sale after a data breach
Person typing on a computer keyboard.

Neopets, an aged website that lets users keep virtual pets and take care of them, just suffered a major data breach. Aside from the personal data of over 69 million users, the hacker was able to obtain the website's source code.

This isn't the first time Neopets has faced a massive leak, but this time around, user data is currently being sold for crypto -- and the leak includes more than just usernames and passwords.

Read more