Data Breaches

Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach Cover-Up

Former Uber security chief Joe Sullivan was sentenced to probation and community service for covering up the data breach suffered by the ride-sharing giant in 2016.

Uber

Former Uber security chief Joe Sullivan was sentenced on Thursday to three years of probation for covering up a data breach suffered by the ride-sharing giant in 2016.

Sullivan was charged in August 2020 and found guilty by a jury in October 2022. Before the sentencing, prosecutors were hoping for 15 months in prison, while the defense wanted probation, which was the ultimate outcome, allowing the former chief security officer (CSO) to avoid prison time. In addition to probation, Sullivan must perform 200 hours of community service as part of the sentencing.

Sullivan, who worked at Uber between April 2015 and November 2017, was accused of obstructing an FTC investigation into a data breach suffered by the company in 2014. While that older incident was being investigated, Sullivan learned of another, larger breach, but decided not to disclose it.

That larger incident occurred in 2016 and it involved hackers stealing the information of more than 50 million Uber users and drivers. 

The attackers extorted Uber and were paid $100,000 through the company’s bug bounty program. They were allegedly instructed by Sullivan to sign non-disclosure agreements falsely claiming that no data had been stolen.

The full impact of the incident came to light roughly one year later, after Uber appointed a new CEO. Sullivan was terminated after it was revealed that he had hidden the full extent of the hack from Uber’s new management.

Advertisement. Scroll to continue reading.

The hackers, two individuals from Canada and Florida, pleaded guilty in 2019. They seem to have been instrumental in the prosecution’s case against the former CSO.

Sullivan is a former federal prosecutor who led security programs at several Silicon Valley companies, including eBay, PayPal and Facebook before his stint at Uber.

The case is being closely watched by many CISOs and other cybersecurity leaders who are concerned about the potential liability for their decisions and disclosures related to breaches and security incidents.

“The international CISO community has been watching this one very closely, and hypothesising about the repercussions for some time,” Neil Thacker, CISO, EMEA, Netskope told SecurityWeek previously. “There is very little doubt among my peers that this case was about a serious misjudgment on the part of a CISO, but hindsight is a wonderful thing and we will probably never fully understand the complex factors and influences that led to his decisions. One of the biggest concerns within the community is an acknowledgment of the possible pressure that may have been exerted from other internal authorities upon the CISO, which led him to make the decisions.”

Related: Industry Reactions to Conviction of Former Uber CSO Joe Sullivan

Related: Uber Data Leaked Following Breach at Third-Party Vendor

Related: Uber Settles With Federal Investigators Over 2016 Data Breach Coverup

Related Content

CISO Strategy

Martin brings experience from Coinbase, Palantir, Amazon, and the U.S. Army to lead Uber's cybersecurity and enterprise security organization.

CISO Conversations

Carl Froggett combines CISO and CIO. He currently occupies both positions at Deep Instinct. Before then, he was CISO at Citi for almost 17...

Cyber Insurance

Boards may ignore alerts, but they listen to losses: new data from Resilience links security gaps directly to financial impact.

CISO Conversations

Sophos’ Ross McKerchar discusses leadership at scale, retaining talent, defending against AI-enabled threats, and the industry’s growing trust problem.

Artificial Intelligence

CISOs face a shrinking window to prepare as AI models like Mythos collapse the gap between vulnerability discovery and exploitation, driving a new era...

CISO Conversations

Cardwell started her career at Netscape, become a VP of engineering at American Express, CISO at UnitedHealth Group, and now CISO in Residence at...

CISO Strategy

The goal isn’t about preventing every attack but about keeping the business running when attacks succeed.

CISO Conversations

Timothy Youngblood was CISO at Dell, CISO at Kimberley-Clark, VP & CISO at McDonald’s, and SVP, CSO & Product Security Officer at T-Mobile.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version