Uber's Former Security Chief Charged With Covering Up Massive 2016 Hack

The case was believed to be first time a corporate information security officer has been charged with concealing a hack.

Advertisement
By Retuers | Updated: 21 August 2020 12:55 IST
Highlights
  • The complaint alleges then-CEO Kalanick was aware of Sullivan’s actions
  • Sullivan arranged to pay the hackers $100,000 under Uber’s programme
  • Sullivan now works as chief information security officer at Cloudflare

The complaint alleges that then-CEO Travis Kalanick was aware of Sullivan’s actions

In an unprecedented case, a former chief security officer for Uber was criminally charged on Thursday with trying to cover up a 2016 hacking that exposed personal information of about 57 million of the ride-hailing company's customers and drivers.

The US Department of Justice charged Joseph Sullivan, 52, with felony obstruction of justice, saying he took "deliberate steps" to keep the Federal Trade Commission from learning about the hack while the agency was monitoring Uber security in the wake of an earlier breach.

The case was believed to be first time a corporate information security officer has been charged with concealing a hack.

Advertisement

Sullivan, himself a former federal prosecutor, arranged to pay the hackers $100,000 (roughly Rs. 75 lakhs) under Uber's programme for rewarding security researchers who report flaws. That amount was by far the most Uber had paid through the bounty programme, which was not meant to cover theft of sensitive data.

Advertisement

A former chief of security at Facebook, Sullivan now works as chief information security officer at Cloudflare.

In past interviews, security staff said the Uber payout was intended to force the hackers into the open to accept the money and to ensure that the data, especially driver's license information on Uber contractors, was destroyed.

Advertisement

The complaint says Sullivan had the hackers sign non-disclosure agreements that falsely stated they had not stolen data. It alleges that then-CEO Travis Kalanick was aware of Sullivan's actions.

A spokeswoman for Kalanick declined to comment. A spokesman for Sullivan said that the charges had no merit, that Sullivan had worked with his colleagues on the case and that disclosure matters were decided by the legal department.

Advertisement

“If not for Mr. Sullivan's and his team's efforts, it's likely that the individuals responsible for this incident never would have been identified at all,” said spokesman Brad Williams.

Kalanick's successor as CEO, current Uber chief Dara Khosrowshahi, disclosed the payoff, then fired Sullivan and a deputy after learning the extent of the breach. Uber then paid $148 million (roughly Rs. 1108 crores) to settle claims by all 50 US states and Washington DC that it had been to slow to reveal the hack.

The Uber case will resonate for the increasing number of companies that deal directly with hackers.

Many have bounty programmes like Uber's, which are generally seen as a tool to improve security and provide an incentive for hackers to stay within the law. But some participants do not play by the rules.

In the Uber case, the FBI noted, the two main hackers went on to attack other companies, which the agency said could have been averted if Sullivan had gone first to law enforcement. Both have pleaded guilty and are awaiting sentencing.

The case also suggests that companies that pay hackers to get rid of ransomware, malicious programs that encrypt their files, are not exempt from requirements to report losses of personally sensitive information.

© Thomson Reuters 2020


Buying a budget TV online? We discussed how you can pick the best one, on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Uber, Hacking, Security Breach.
Advertisement

Related Stories

Popular Mobile Brands
  1. Apple's iOS 26.1 May Launch on This Date, Followed By iOS 26.2 Beta Rollout
  2. Realme GT 8 Pro Aston Martin F1 Limited Edition Launch Date Revealed
  3. Here Are the Best Smartphones Under Rs 20,000 With AMOLED Display
  4. Vivo Y19s 5G Launched in India With 6,000mAh Battery: See Price
  5. Samsung Galaxy S26 Series Could Launch on This Date
  6. Red Magic 11 Pro Launched in Global Markets With Slightly Smaller Battery
  7. Apple is Expected to Launch These Products Next Year
  8. Poco F8 Pro, F8 Ultra Set for Global Launch 'Really Soon', Tipster Claims
  9. Oppo Reno 15 Series Might Launch in India Next Month
  1. Rockstar Games Co-Founder Says GTA Games Won't Work if Set Outside the US
  2. Iran Tackles Unauthorised Crypto Mining After 95 Percent of Bitcoin Mining Devices Found Operating Illegally
  3. Red Magic 11 Pro Launched Globally With Snapdragon Elite Gen 5, Slightly Smaller Battery: Price, Specifications
  4. Microsoft AI Chief Mustafa Suleyman Calls the Idea of Conscious AI ‘Absurd’: Report
  5. Poco F8 Ultra, Poco F8 Pro Global Launch Around the Corner, Tipster Claims
  6. India’s Smartphone Shipments Grew 5 Percent YoY in Q3 2025; Apple Enters List of Top 5 Phone Makers: Counterpoint
  7. Polymarket Banned By Romanian Regulator for Illegal Crypto Betting Following $600 Million Election Wagers
  8. Samsung Galaxy A57 Model Number Reportedly Surfaces on Company's Test Server
  9. Arc Raiders Hits Over 300,000 Concurrent Players on Steam After Launch
  10. Realme C85 5G, Realme C85 Pro 4G Launched With 7,000mAh Battery: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.