A vulnerability in email allows almost anyone to send emails on behalf of the company.

See also: Uber: Tracks your flight to have a taxi waiting for you as soon as you land!
The researcher who discovered this flaw warns that this vulnerability can be abused by hackers to send emails to 57 million Uber users and drivers, whose information was leaked in a data breach in 2016.
The company appears to be aware of the flaw, but has not taken any action to fix it for now.
Security researcher Seif Elsallamydiscovered the flaw in question in its systems.
These emails, sent from Uber servers, will appear legitimate to an email provider and will bypass spam filters.
See also: Uber and Lyft will offer free rides to vaccination centers
Imagine receiving a message from the service saying: “Uber is coming to you now” when you never requested a ride.

On New Year's Eve 2021, the researcher responsibly reported the vulnerability to Uber through the HackerOne bug bounty program.
However, his report was rejected as being “out of scope” on the incorrect assumption that exploiting the technical flaw itself required some form of social engineering.
It seems this isn't the first time the company has dismissed this particular flaw.
Researchers Soufiane el Habti and Shiva Maharaj claim they had also reported the issue to Uber without success.
See also: Uber: $1.1 million to blind woman who drivers refused to transport 14 times
By exploiting this unpatched vulnerability, hackers could potentially send targeted phishing scams to millions of Uber users who were previously affected by the breach.
Uber users, staff, drivers, and partners should be wary of any phishing emails sent by the service even if they appear trustworthy, as exploitation of this flaw by malicious actors remains possible.
