In light of the recent Uber cybersecurity hack, we wanted to provide a few important reminders to help you keep eMoney’s security shield strong. The hacker bypassed multi-factor authentication through MFA fatigue and used a message in Slack – a chat system similar to Microsoft Teams – to compromise Uber’s security. Please read the helpful tips below to remain vigilant.
- In these recent attacks, the malicious actors used a technique known as an “MFA fatigue” attack – which means the malicious actors send repeated login notifications to an employee until the employee approves the authentication request for MFA. Basically, the malicious actor wears the employee down. Once approved, the attacker is in.
- For eMoney, this type of attack would be targeted against our Okta Push Authentication platform.
- When you receive an authentication confirmation request, it is imperative that you make sure that you have initiated that request and that the associated location tied to that request is accurate.
- If you receive a notification from an unknown or inaccurate location, DO NOT click on the notification. Report it to the Security Team.
- If we are unable to remain diligent in preventing these types of attacks then as a company we will need to abandon push authentication and revert back to token-based in which you manually enter the code.
- Do not reply to text or chat messages that seem suspicious. Hackers use social engineering to manipulate individuals into divulging confidential or personal information that can be used for fraudulent purposes. Confirm the individual’s identity by calling them or messaging them directly.
- Block the number, report as junk, and delete the message if you confirm the message was not from who they claimed to be.
- Complete your eMoney cybersecurity training. All employees are required to complete monthly security trainings through Wombat – our security education platform – available in Okta. These trainings provide helpful tips to prevent attacks like Uber.
- All Developers and QA Analysts are required to complete separate developer security training within Veracode as part of eMoney’s compliance efforts.
- October is Cybersecurity Awareness Month. Stay tuned throughout the month for more tips about cyber safety!
Leave a Reply