Firewall Daily

Former Uber Security Chief Convicted of Hiding 2016 Hacking

Joe Sullivan, the former chief security officer for Uber, was convicted for hiding details of a hack that could have affected over 57 million Uber users, including customers and drivers.

The charges were filed for the 2016 cyberattack wherein a hacker group stole the users’ personal information from the company’s databases. The stolen data included the names, email addresses, and contact details of 50 million users and 7 million Uber drivers. The latter compromised the permanent addresses and license numbers of Uber drivers.

The jury convicted Sullivan for two counts, including one for obstructing justice for hiding the breach to the FTC and another for misprision, which is concealing a fraud from legal authorities in the US, the New York Times reported.

Uber data breach 2016 and Joe Sullivan

Joe Sullivan has served as a security executive in tech giants such as Facebook and Cloudflare. According to the prosecution, the hackers used a similar pattern as was noted in the 2014 Uber breach, where the company suffered a cyberattack that left details of over 100,000 individuals exposed. The 2016 case went under the rug because Sullivan hindered any detection and media coverage of the breach and kept the hack hidden from the general public, a report stated.

The 2016 Uber breach occurred when threat actors accessed Uber’s Amazon Web Services (AWS) storage. The threat actors then downloaded the database backups, which included the data of Uber customers as well as Uber drivers. The hackers then contacted Uber for a ransom in exchange for deleting the stolen information.

The American mobility company paid a ransom to the threat actors under the disguise of a Bug Bounty program. The hackers were finally caught by authorities in 2019 and pleaded guilty to hacking into the company’s database and stealing the personal information of users and drivers.

Joe Sullivan charges over Uber data breach

In the hearing that began earlier this September, the prosecutors showed evidence against Sullivan and shared the details of the hack and the payment method used for the ransom. The prosecutors also claimed that the former Uber CEO Travis Kalanick knew about the incident and the payment made to the hackers. They also claimed that Sullivan didn’t inform Uber’s general counsel about the breach, and the new CEO, Dara Khosrowshahi, was unaware of the incident.

Bloomberg reports that Sullivan didn’t reveal the breach to the company to protect his reputation because, as a chief security officer for Uber, he was supposed to protect the company from cyberattacks and hackers after joining the organization in 2015. The report added that Sullivan could face up to eight years in prison, however, there is a possibility that the sentence may be reduced.

Under the new CEO, Dara Khosrowshahi, Uber has fired Sullivan, publicly admitted to the breach, and paid $148 million in civil litigation over the breach to all 50 states. However, despite all the claims, Sullivan’s lawyers tried justifying his action stating that he did all that to prevent the leak of users’ data and even informed the CEO and other necessary personnel about the incident.

Sullivan and his team also identified the hackers and got them to sign NDAs under their real names to not leak any of the stolen data in exchange for the ransom from the Bug Bounty program.

Avantika

Avantika Chopra is the Associate Editor at The Cyber Express, where she brings over seven years of in-depth journalism experience to the forefront of cybersecurity news. With a keen eye for detail and a passion for the latest in cyber defense technologies, Avantika has been instrumental in reporting and shaping the narrative around digital security trends and threats. Her work emphasizes the importance of understanding cybersecurity not just as a technical field, but as a critical element of modern governance and personal safety. When she's not dissecting the latest cyber threats, you might find her caring for her garden or planning her next adventure.

Recent Posts

The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape

AI fraud, deepfake probes, SME cyber warnings, and ransomware cases highlight rising global risks in this week’s Cyber Express roundup.

2 days ago

French National Bank Authority Breach Exposed 1.2 Million Accounts

French national bank authority confirmed a major data breach affecting 1.2 million bank accounts after a malicious actor stole credentials…

2 days ago

What Big Tech Leaders Said On AI’s Future at India AI Impact Summit 2026

The real success of AI will not only depend on how powerful the technology becomes, but on how safely, fairly,…

2 days ago

Two Petabytes Worth Data of Israeli’s Siphoned, Says Cyber Head

Israel data breach totals two petabytes, with phishing up 35% and cyber influence attacks rising 170%, says Yossi Karadi.

2 days ago

Cyberattack Forces Clinic Closures, Surgery Cancellations at University of Mississippi Medical Center

The UMMC cyberattack halted surgeries, closed clinics statewide and triggered a federal probe into potential patient data exposure.

2 days ago

First Android Malware Weaponizes Gemini AI to Evade Detection, Maintain Persistence

ESET researchers discovered PromptSpy, the first known Android malware to integrate generative AI directly into its execution flow, marking a…

3 days ago

This website uses cookies. By continuing to use this website you are giving consent to cookies being used.

Read More