Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach Cover-Up

Former Uber security chief Joe Sullivan was sentenced to probation and community service for covering up the data breach suffered by the ride-sharing giant in 2016.

Uber fine

Former Uber security chief Joe Sullivan was sentenced on Thursday to three years of probation for covering up a data breach suffered by the ride-sharing giant in 2016.

Sullivan was charged in August 2020 and found guilty by a jury in October 2022. Before the sentencing, prosecutors were hoping for 15 months in prison, while the defense wanted probation, which was the ultimate outcome, allowing the former chief security officer (CSO) to avoid prison time. In addition to probation, Sullivan must perform 200 hours of community service as part of the sentencing.

Sullivan, who worked at Uber between April 2015 and November 2017, was accused of obstructing an FTC investigation into a data breach suffered by the company in 2014. While that older incident was being investigated, Sullivan learned of another, larger breach, but decided not to disclose it.

That larger incident occurred in 2016 and it involved hackers stealing the information of more than 50 million Uber users and drivers. 

The attackers extorted Uber and were paid $100,000 through the company’s bug bounty program. They were allegedly instructed by Sullivan to sign non-disclosure agreements falsely claiming that no data had been stolen.

The full impact of the incident came to light roughly one year later, after Uber appointed a new CEO. Sullivan was terminated after it was revealed that he had hidden the full extent of the hack from Uber’s new management.

Advertisement. Scroll to continue reading.

The hackers, two individuals from Canada and Florida, pleaded guilty in 2019. They seem to have been instrumental in the prosecution’s case against the former CSO.

Sullivan is a former federal prosecutor who led security programs at several Silicon Valley companies, including eBay, PayPal and Facebook before his stint at Uber.

The case is being closely watched by many CISOs and other cybersecurity leaders who are concerned about the potential liability for their decisions and disclosures related to breaches and security incidents.

“The international CISO community has been watching this one very closely, and hypothesising about the repercussions for some time,” Neil Thacker, CISO, EMEA, Netskope told SecurityWeek previously. “There is very little doubt among my peers that this case was about a serious misjudgment on the part of a CISO, but hindsight is a wonderful thing and we will probably never fully understand the complex factors and influences that led to his decisions. One of the biggest concerns within the community is an acknowledgment of the possible pressure that may have been exerted from other internal authorities upon the CISO, which led him to make the decisions.”

Related: Industry Reactions to Conviction of Former Uber CSO Joe Sullivan

Related: Uber Data Leaked Following Breach at Third-Party Vendor

Related: Uber Settles With Federal Investigators Over 2016 Data Breach Coverup

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

In cyber-physical systems (CPS), just one hour of downtime can outweigh an entire annual security budget. Learn how to master the Return on Security Investment (ROSI) to align security goals with the bottom-line priorities.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Malwarebytes has named Chung Ip as Chief Financial Officer.

Semperis has appointed John Podboy as Chief Information Security Officer.

Randy Menon has become Chief Product and Marketing Officer at One Identity.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.