Uber logins available for sale in the Deep Web

Security experts have discovered al least two different vendors offering stolen Uber customer logins in a black market on the Dark Web.

ArsTechnica has discovered that two vendors on a marketplace in the underground are offering active Uber credential.

During the weekend the vendors “Courvoisier” “ThinkingForward” are claiming to sell valid Uber logins respectively for $1 and 5$ each on the AlphaBay Market.  The AlphaBay Market is a relatively new black marketplace, it was launched in late 2014.

“The credentials provided will be a valid login for the Uber website for which you can use to order phones from completely free. (You can find the guide in our store if you’re unaware on the how-to).” Wrote Courvoisier. 

The vendor ThinkingForward, which is offering the Uber login for $5, guarantees  that they are valid credentials.

“I will guarantee that they are valid and live ONLY. Discounts on bulk purchases,” ThinkingForward writes on his product listing.“It’s terrifying that this information is out there. [It’s a] massive breach of privacy.”

I have searched for the Uber credential in the Tor MarketPlace, it seems that the vendor has sold more that one hundred logins.

Ars have tried to contact the sellers without success, meanwhile Motherboard contacted once vendor that claimed to have “thousands” login for sale and was also open to a “try and buy” option. Motherboard also reached one of the Uber users impacted by the alleged data breach as reported below discovering that the login are original.

“Motherboard reached out to one of the users whose email address and password was put up for sale: James Allan, sales director for OISG, a technology solutions company.

Allan confirmed that the username and password Motherboard had seen were correct, as well as the expiry date on his personal credit card. He doesn’t actually use Uber anymore, and the last trip he booked was in December 2013.

“Bloody hell,” Allan said over the phone, when he was told what his password was.

He was “extremely surprised” by the revelation, he said. Allan also said that he doesn’t use the internet much for financial transactions, preferring cash “for this very reason.” states Motherboard.

Uber spokeswoman Trina Smith contacted Ars to confirm that the company did not find evidence of a data breach.

“Attempting to fraudulently access or sell accounts is illegal and we notified the authorities about this report,” Smith wrote. “This is a good opportunity to remind people to use strong and unique usernames and passwords and to avoid reusing the same credentials across multiple sites and services.”

In February the giant Uber announced a data breach that resulted in unauthorized access to the driver partner license numbers of roughly 50,000 of its drivers, anyway the news reported by Ars seems to be not linked to the previous incident according Uber.

Uber is currently investigating the origin of login, at the time I’m writing it is unclear where the data came from and how many users were impacted.

Pierluigi Paganini

(Security Affairs –  Uber,  cybercrime)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

FIN7 targeted a large U.S. carmaker with phishing attacks

BlackBerry reported that the financially motivated group FIN7 targeted the IT department of a large…

4 hours ago

Law enforcement operation dismantled phishing-as-a-service platform LabHost

An international law enforcement operation led to the disruption of the prominent phishing-as-a-service platform LabHost.…

9 hours ago

Previously unknown Kapeka backdoor linked to Russian Sandworm APT

Russia-linked APT Sandworm employed a previously undocumented backdoor called Kapeka in attacks against Eastern Europe since…

14 hours ago

Cisco warns of a command injection escalation flaw in its IMC. PoC publicly available

Cisco has addressed a high-severity vulnerability in its Integrated Management Controller (IMC) for which publicly…

16 hours ago

Linux variant of Cerber ransomware targets Atlassian servers

Threat actors are exploiting the CVE-2023-22518 flaw in Atlassian servers to deploy a Linux variant of…

1 day ago

Ivanti fixed two critical flaws in its Avalanche MDM

Ivanti addressed two critical vulnerabilities in its Avalanche mobile device management (MDM) solution, that can…

2 days ago

This website uses cookies.