Uber's incident began on 15 September 2022 with a contractor's phone, and it began with a password the contractor had already lost. Uber said afterwards that it believed the credentials had been stolen by malware on the contractor's personal device and then bought on a dark web marketplace, so the attacker arrived at the login page holding a valid password with only the second factor in his way. He solved that by repetition, firing login approval requests at the contractor's phone over and over. By the account he later gave a security researcher, the buzzing ran for more than an hour before a message arrived on WhatsApp from someone claiming to be Uber IT, explaining that the notifications would stop once the request was accepted. It was accepted.

What was waiting on the other side is the detail the industry has never stopped citing. By the intruder's own account, and the screenshots he sent to researchers, an internal network share held a set of PowerShell scripts, one of which carried hardcoded credentials for a domain administrator account on Thycotic — Uber's privileged access management system, the place its other credentials were kept; Uber has never publicly confirmed that detail. The intruder then posted a message in a company-wide Slack channel stating that Uber had been breached, and enough employees answered with jokes and emoji that it was read as a prank before it was understood as an incident. Uber took Slack offline. The company confirmed he reached Google Workspace and Slack, downloaded internal messages, opened finance invoicing tools and entered its HackerOne dashboard, but said production systems, user accounts and the databases holding trip history and payment details were never reached.

Three days later, on 18 September, a new account on GTAForums calling itself teapotuberhacker posted download links to some ninety video files taken from an unreleased Grand Theft Auto — roughly fifty minutes of work-in-progress footage from a game Rockstar Games had confirmed was in development but had never shown. Take-Two Interactive issued takedown notices within hours; the clips were already everywhere. Rockstar confirmed the intrusion on 19 September and said it did not expect disruption to its live services or its projects. Evidence given at the later trial described the Rockstar access being carried out from a hotel room, using a phone, an Amazon Fire TV Stick and the room's television. On 22 September, City of London Police arrested a seventeen-year-old in Oxfordshire.

The seventeen-year-old was Arion Kurtaj, already on bail over earlier Lapsus$ intrusions; police had placed him in that hotel for his own safety after he was identified within the hacking community. Psychiatrists found him unfit to plead, so in August 2023 a jury at Southwark Crown Court was asked only whether he had committed the acts, not whether he was guilty of them, and found that he had, across twelve counts. On 21 December 2023 he was made subject to an indefinite hospital order, the judge saying he remained determined to offend again if the opportunity arose. It did not end there. Reporting restrictions were lifted on 14 July 2026, by which point he had been assessed as fit to stand trial, moved out of the secure hospital into prison, and listed for retrial.

Also that month · An interface with no lock

Optus, and a third of a country

Optus disclosed on 22 September 2022 that customer records had been taken, saying it had detected the unauthorised access two days earlier, on 20 September. The exposure covered up to around ten million current and former customers — close to a third of Australia's population — with names, dates of birth, addresses, phone numbers and email addresses, and for about 2.1 million of them at least one identity document number, of which roughly 1.2 million were current and valid. Optus described the incident as a sophisticated attack that required knowledge of its systems; the government rejected that framing outright, the home affairs minister saying responsibility rested with Optus, and reporting pointed to an internet-facing API that required no authentication and returned records against sequential customer identifiers. A poster on a criminal forum demanded about a million US dollars in Monero, published a sample of ten thousand records as proof, then deleted the demand and apologised. The apology changed nothing; the records were already out.

Also that month · Second-largest district in America

The school district that said no

Los Angeles Unified detected ransomware on its network over the Labor Day weekend, on the night of 3 September 2022. Classes went ahead on the Tuesday as scheduled, but staff and students across more than a thousand schools serving roughly 600,000 pupils lost access to email, Google Drive and the Schoology learning platform. The district later revised its own account, saying investigators had established the intruders were inside from 31 July — five weeks before anything visibly broke. Vice Society, a group the FBI and CISA had warned about in a joint advisory published on 6 September for disproportionately targeting the education sector, claimed the attack and set a payment deadline of 4 October. On 30 September the district said publicly that it would not pay, arguing that public money was better spent on students than handed to a crime syndicate. The files appeared on the gang's leak site within days; Vice Society claimed roughly 500 gigabytes, and the district later confirmed that contractors' Social Security numbers were among the material published.

India desk · September 2022

Sixteen million complaints, and a deadline

On 23 September 2022, researchers at CloudSEK and Cyble found a threat actor calling itself LeakBase offering a database it said held the records of sixteen million users of Swachhata — the municipal complaints platform run under the Swachh Bharat Mission by the Ministry of Housing and Urban Affairs. The dump was around six gigabytes, drawn from a SQL database named swachh_manch, and contained usernames, email addresses, password hashes, mobile numbers, one-time passwords, last-login times and IP addresses; the researchers counted 101,718 unique email addresses and 15,835,111 unique mobile numbers. Their reading was that an administrator account had been compromised in April 2022, possibly through an exposed database interface — an assessment by the analysts who examined the sample, not a published forensic finding, and not something the ministry confirmed.

Two days later, on 25 September, CERT-In's extended compliance deadline arrived for the categories granted more time in June: micro, small and medium enterprises, data centres, virtual private server providers, cloud service providers and VPN providers. From that date the directions of 28 April 2022 bound them in full — six hours to report a listed incident from the moment it came to notice, 180 days of logs held within India, and for VPN providers five years of subscriber records. Several international VPN companies had already pulled their servers out of the country rather than comply. On 2 September the Reserve Bank had issued its Guidelines on Digital Lending, giving lenders until 30 November to bring existing digital loans into line. India still had no data protection statute: the Personal Data Protection Bill had been withdrawn from Parliament on 3 August, and its replacement was eleven months from passage.

AI Tech desk · September 2022

Whisper, and the end of the waitlist

OpenAI spent the month giving things away. On 21 September 2022 it released Whisper, a speech recognition model published with its code and weights, able to transcribe dozens of languages, identify which one it was hearing and translate the rest into English. Of everything shipped that September, Whisper aged best: it became the default open transcription layer, wired into products that otherwise have nothing to do with OpenAI. A week later, on 28 September, the company removed the waitlist from DALL·E, saying more than 1.5 million users were already generating over two million images a day. Meta answered on 29 September with Make-A-Video, a research system that turned a text prompt into a soundless clip a few seconds long — never released to the public, but an early marker on the road to the text-to-video generators that arrived in earnest from 2024. Nobody outside OpenAI knew it yet, but ChatGPT was two months away.

Digital Guard desk · September 2022

Two mergers, one Monday

The consolidation arrived on a single day. On 12 September 2022 NortonLifeLock completed its merger with Avast, just over a year after the deal was announced and days after the United Kingdom's competition regulator issued the final report clearing it — the end of a review that had gone to a full phase-two inquiry over how much competition consumer security could stand to lose. The combined company said it served half a billion users, bringing Norton, Avast, AVG and Avira under one roof; that November it renamed itself Gen Digital, the name those brands still sit under today. The same day, Google closed its $5.4 billion acquisition of Mandiant — its largest security purchase — folding the incident response firm into Google Cloud while keeping the name, and laying the foundation of the threat intelligence business Google runs today. On 20 September CrowdStrike used its Fal.Con conference to announce it would acquire Reposify, an external attack surface management company, on undisclosed terms: the same instinct at smaller scale, endpoint vendors no longer content to watch endpoints alone.

⏳ Time capsule — September 2022

  • Queen Elizabeth II died at Balmoral on 8 September, aged 96, after seventy years on the throne; her state funeral was held in London on 19 September.
  • Two tennis careers ended three weeks apart — Serena Williams played her last match on 2 September, losing a US Open third round to Ajla Tomljanović, and Roger Federer played his on 23 September, in doubles alongside Rafael Nadal at the Laver Cup in London.
  • Apple announced the iPhone 14 on 7 September, adding Emergency SOS via satellite and crash detection.
  • NASA's DART spacecraft struck the asteroid Dimorphos on 26 September, shortening its orbit around Didymos by about 32 minutes — the first time humanity deliberately changed the motion of a celestial body.
Where it stands today — 2026

The month the second factor stopped being enough

September 2022 is the month that pushed multi-factor authentication past the push notification. Prompt-bombing was not new, but Uber made it legible to boards, and within months the defence had a vocabulary: number matching, phishing-resistant factors, hardware keys. Microsoft began enforcing number matching in its authenticator app in May 2023. The second lesson took longer to land — that a domain administrator password sitting in a script on a network share defeats every control layered above it — and secrets scanning entered build pipelines largely because of incidents shaped like this one. The Australian half of the month moved law rather than practice: within weeks of Optus, Parliament raised the maximum privacy penalty to the greater of A$50 million, three times any benefit obtained, or thirty per cent of adjusted turnover.

Those penalties do not reach Optus itself. When the Information Commissioner filed civil penalty proceedings in the Federal Court in August 2025, alleging that the privacy of roughly 9.5 million Australians was seriously interfered with between October 2019 and September 2022, the conduct predated the new maximums, so the case runs under the older figure of about A$2.22 million per contravention — with the Commissioner arguing for a contravention per affected person. Los Angeles Unified's refusal to pay sits in the same line as Royal Mail's four months later, in the January 2023 edition of this archive. And the teenager at the centre of the month is, as this edition is restored in August 2026, in prison awaiting a trial that was supposed to have been settled three years ago.