Supply chain ⛓ Supply Chain

Uber Third-Party Breach (March 2023)

📅 2023-03-01 🏢 Genova Burns
Primary Source ↗

Incident Details

Uber suffers another data breach after law firm’s servers attacked. This is the third time in six months that Uber has been the victim of a data breach. Uber has found itself in the middle of yet another data breach, this time as a result of private driver data being stolen from a third-party law firm. Genova Burns, a mid-sized law firm based in New Jersey, has written to the affected Uber drivers that confidential information belonging to them, such as their social security and tax identification numbers, have been stolen in a data breach of its IT systems. Third-party company: Genova Burns.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Genova Burns
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2023-03-01 Breach occurred
  2. 2023-04-04 Publicly disclosed