Warning for Uber users: Fraudulent messages target the theft of payment card data

A technical report has warned of a new phishing campaign targeting Uber app users through fake emails that suggest there is a problem with the payment method linked to their account, with the aim of stealing users’ financial data. The website AppleInsider reported that the campaign relies on messages that appear official and claim that a payment card has expired, urging users to update their details urgently, exploiting the sense of urgency to push victims into clicking on fake links.
The report clarified that the attack does not depend on hacking the Uber app or exploiting a security vulnerability within it, but rather on social engineering tactics. It noted that there are indicators that can help identify the fake messages, such as the use of an email address not belonging to the company’s official domain, the absence of the user’s personal details, or the message being sent to a large number of recipients simultaneously.
Experts advise against interacting with any links received via email and recommend logging directly into the Uber app or visiting the official website to verify any notifications related to the account. They emphasized that this type of fraud also targets banking services, shopping platforms, and other applications.