HomeSecurityHackers used Uber user accounts for online purchases

Hackers used Uber user accounts for online shopping

Uber has fixed a serious flaw that allowed hackers to call rides and charge various other purchases to customer accounts using the victim's email address or phone number.

The bug, which was discovered by Anand Prakesh, a security researcher, could also be used to track a user's location.

Uber hackers

Prakesh was able to access an account's unique user ID, or " access token ," by providing a phone number or email address associated with an account to Uber's API

APIs send information from Uber to app developers, usually to ensure their apps work with Uber, like Google Maps, which lets you call a ride from your exact location.

The company rewarded the security researcher with $6,500 as part of its Bug Bounty program. Uber generally pays up to $50,000 for new vulnerability findings. The bug was fixed just a few days after it was reported.

An Uber spokesperson said the flaw was not exploited by hackers, adding that Uber has automated protections that detect suspicious activity, such as a login from a new device, and will alert a user by either asking them to confirm the activity or reset their credentials.

Uber's bug bounty program has paid out over $2 million to more than 600 researchers around the world who help protect the platform.

The hijacking accounts method was also used to bring down Facebook by hackers in October 2018.

Using a similar method of stealing “access tokens,” they were able to compromise 30 million Facebook. It’s unclear who orchestrated the attack. The Federal Bureau of Investigation launched an investigation in October.

Uber, which is currently valued at around $57 billion, operates in 785 cities around the world.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS