Uber Data Breach: Former Security Chief Convicted by US Jury for Covering Up Massive 2016 Hack

Uber's former security chief Joseph Sullivan was found guilty of obstructing justice and concealing knowledge that a federal felony had been committed.

Advertisement
By Associated Press | Updated: 6 October 2022 14:25 IST
Highlights
  • Uber's former chief of security was found guilty of hiding a 2016 hack
  • He was found guilty of obstructing the work of FTC
  • Uber investigated the data breach in 2017

Joseph Sullivan was found guilty of obstructing a US FTC probe

The former chief security officer for Uber was convicted Wednesday of trying to cover up a 2016 data breach in which hackers accessed tens of millions of customer records from the ride-hailing service.

A federal jury in San Francisco convicted Joseph Sullivan of obstructing justice and concealing knowledge that a federal felony had been committed, federal prosecutors said.

Advertisement

Sullivan remains free on bond pending sentencing and could face a total of eight years in prison on the two charges when he is sentenced, prosecutors said.

“Technology companies in the Northern District of California collect and store vast amounts of data from users,” US Attorney Stephanie M. Hinds said in a statement. “We will not tolerate concealment of important information from the public by corporate executives more interested in protecting their reputation and that of their employers than in protecting users.”

Advertisement

It was believed to be the first criminal prosecution of a company executive over a data breach.

A lawyer for Sullivan, David Angeli, took issue with the verdict.

Advertisement

“Mr. Sullivan's sole focus — in this incident and throughout his distinguished career — has been ensuring the safety of people's personal data on the internet,” Angeli told the New York Times.

An email to Uber seeking comment on the conviction wasn't immediately returned.

Advertisement

Sullivan was hired as Uber's chief security officer in 2015. In November 2016, Sullivan was emailed by hackers, and employees quickly confirmed that they had stolen records on about 57 million users and also 600,000 driver's license numbers, prosecutors said.

After learning of the breach, Sullivan began a scheme to hide it from the public and the Federal Trade Commission, which had been investigating a smaller 2014 hack, authorities said.

According to the US attorney's office, Sullivan told subordinates that “the story outside of the security group was to be that ‘this investigation does not exist,'" and arranged to pay the hackers $100,000 (roughly Rs. 82 lakh) in bitcoin in exchange for them signing non-disclosure agreements promising not to reveal the hack. He also never mentioned the breach to Uber lawyers who were involved with the FTC's inquiry, prosecutors said.

“Sullivan orchestrated these acts despite knowing that the hackers were hacking and extorting other companies as well as Uber," the US attorney's office said.

Uber's new management began investigating the breach in the fall of 2017. Despite Sullivan lying to the new chief executive officer and others, the truth was uncovered and the breach was made public, prosecutors said.

Sullivan was fired along with Craig Clark, an Uber lawyer he had told about the breach. Clark was given immunity by prosecutors and testified against Sullivan.

No other Uber executives were charged in the case.

The hackers pleaded guilty in 2019 to computer fraud conspiracy charges and are awaiting sentencing.

Sullivan was convicted of of obstruction of proceedings of the Federal Trade Commission and misprision of felony, meaning concealing knowledge of a felony from authorities.

Meanwhile, some experts have questioned how much cybersecurity has improved at Uber since the breach.

The company announced last month that all its services were operational following what security professionals called a major data breach, claiming there was no evidence the hacker got access to sensitive user data.

The lone hacker apparently gained access posing as a colleague, tricking an Uber employee into surrendering their credentials. Screenshots the hacker shared with security researchers indicate they obtained full access to the cloud-based systems where Uber stores sensitive customer and financial data.

It is not known how much data the hacker stole or how long they were inside Uber's network. There was no indication they destroyed data.

What do we know about the upcoming Pixel 7 and 7 Pro? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: uber, Joseph Sullivan, US jury
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Fusion Review
  2. Google Puts Together A-Team to Build Better Coding Models Than Anthropic
  3. Oppo Pad 5 Pro With 13,380mAh Battery Debuts Alongside Pad Mini: See Prices
  4. Jailer 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  5. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  6. Redmi Pad 2 SE 4G Debuts With 9.7-Inch Display, 7,600mAh Battery: See Price
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.