Supply chain
⛓ Supply Chain
Uber Third-Party Breach (March 2023)
Primary Source ↗Incident Details
Uber suffers another data breach after law firm’s servers attacked. This is the third time in six months that Uber has been the victim of a data breach. Uber has found itself in the middle of yet another data breach, this time as a result of private driver data being stolen from a third-party law firm. Genova Burns, a mid-sized law firm based in New Jersey, has written to the affected Uber drivers that confidential information belonging to them, such as their social security and tax identification numbers, have been stolen in a data breach of its IT systems. Third-party company: Genova Burns.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Genova Burns
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2023-03-01 Breach occurred
- 2023-04-04 Publicly disclosed