Desk live·
ForensicPost
Breaches/Identity/File 22-0915

The Contractor Approved the Eighteenth Prompt

A bought password, a flood of push notifications, and a WhatsApp message claiming to be IT support. Inside the network, the attacker found a PowerShell script with hardcoded admin credentials for the privileged access manager.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUber
ActorLapsus$
S. Rosler11 min readConfidence: medium2 sources reviewed

In September 2022 an attacker reached Uber’s internal systems by buying a contractor’s password, then repeatedly triggering multi-factor push notifications to that person’s device. When the prompts alone did not work, the attacker messaged the contractor on WhatsApp posing as Uber IT support and said approving the next one would stop them. It was approved.

Reporting describes the attacker then finding a PowerShell script on an internal share containing plaintext administrator credentials for the company’s privileged access management system, and from there reaching internal Slack, VPN and source code.

The Second Factor Worked Exactly As Designed

Nothing was bypassed. The push prompt was delivered to the right device, held by the right person, who approved it. The control performed its function and the outcome was still an intrusion, because the function is to ask a human a question and the attack was on the human.

The corpus records the same category at 23-0913, where a synced authenticator turned a second factor into no factor, and at 26-0714, where vishing preceded an SSO compromise. A factor that can be approved under social pressure is a factor that can be socially engineered, and the corpus argues at 26-0703 that the remote-access boundary is where this keeps landing.

The Credentials Were In A File

The escalation did not require a further exploit. It required reading a script that somebody had written to automate something, with the administrator password for the system that holds all the other passwords typed into it.

This is the failure the corpus files at 23-0104, where CircleCI rotated every customer secret, and at 25-0917, where every customer’s firewall configuration sat in one backup store. A privileged access manager exists to stop credentials living in files. It cannot do that if its own credential lives in a file.

Why This File Is Graded Medium

The sequence above is drawn from security-industry accounts and from statements made at the time, and the detail is consistent across them. It has not been established here against a primary incident report, and the specific number of prompts sent is not something this desk can verify — accounts vary and the headline of this file should be read as characterising the technique, not as a counted figure.

How we reported this

Built on security-industry analyses of the incident. The purchase of contractor credentials, the repeated push prompts, the WhatsApp impersonation of IT support, the approval, and the discovery of a PowerShell script holding plaintext privileged-access credentials are consistently reported and are carried on that basis. This desk has not seen a primary incident report, which is why the file is graded medium. The title characterises the technique; no specific prompt count is asserted as fact. No individual is named — the contractor is a victim of the attack, and separate proceedings relating to the incident are outside the scope of this file. Corrections: corrections@forensicpost.com.

Sources
  1. MFA Fatigue Attack: Definition & Defense StrategiesBeyondTrust
  2. What Is MFA Fatigue (Push Bombing)?Security Boulevard
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary