Former Uber security chief sentenced for data breach cover-up

File picture

Former Chief Security Officer for ride-hailing service Uber, Joseph Sullivan, has been sentenced to three years of probation and ordered to pay a $50,000 fine for his attempt to cover up a massive data breach in 2016.

The breach exposed tens of millions of customer records to hackers, and Sullivan was convicted of obstructing justice and concealing the knowledge of a federal felony committed in San Francisco last October.

This marks the first criminal prosecution of a company executive for a data breach.

Sullivan was hired as Uber's Chief Security Officer in 2015 and was emailed by hackers in November 2016, confirming that they had stolen records on about 57 million users and 600,000 driver’s license numbers.

He initiated a plan to hide the breach from the public and the Federal Trade Commission, which had been investigating a smaller 2014 hack.

According to the US attorney's office, Sullivan arranged to pay the hackers $100,000 in bitcoin and never mentioned the breach to Uber lawyers involved with the FTC's inquiry. He also told subordinates that "the story outside of the security group was to be that 'this investigation does not exist'’."

Uber's new management uncovered the truth during an investigation in the fall of 2017, and the breach was made public.

Sullivan was fired along with Uber lawyer Craig Clark, who had been told about the breach. Clark testified against Sullivan after being given immunity by prosecutors. While prosecutors had recommended a 15-month sentence in federal prison, Sullivan's lawyers argued that he had already suffered significant consequences as a result of the case.

The hackers responsible for the breach pleaded guilty in 2019 to computer fraud conspiracy charges and are awaiting sentencing. No other Uber executives were charged in this case.

More from Business

  • India reviewing allegations of antitrust breaches by IndiGo

    India's competition regulator said on Thursday it was reviewing allegations of antitrust violations by budget airline IndiGo following recent flight disruptions that hit air travel nationwide.

  • DXB and DWC boost winter schedules with new routes

    Dubai Airports has entered the winter travel season with one of its strongest networks in history, as Dubai International (DXB) and Dubai World Central - Al Maktoum International (DWC) welcome new airlines and expanded connectivity to meet rising seasonal travel demand.

  • Amazon in talks to invest in OpenAI

    Amazon.com IncĀ is in discussions to invest in OpenAI, the developer of ChatGPT, in a potential deal that could value the artificial intelligence company at over $500 billion, a source familiar with the matter said on Tuesday.

  • DXB to welcome over 4.2 million guests over next two weeks

    Dubai International Airport (DXB) is gearing up to accommodate a surge in travellers over the next two weeks, marking one of the busiest travel periods of the year.

Coming Up