Skip to content
Fri. Dec 5th, 2025
  • Facebook
  • Twitter
  • Instagram
  • Youtube
  • VK
  • Whatsapp

Tech News

Technology News,iPhone Reviews,iPad Reviews

Primary Menu
  • Home
  • NEWS
  • AccessoriesBlocks
  • Insider
  • PodcastExclusive
  • APPS
  • HOW TOS
  • Daily Tips
  • Headlines
  • Home
  • Former Uber Security Chief Guilty of Data Breach Coverup
  • NEWS

Former Uber Security Chief Guilty of Data Breach Coverup

4 min read

The conviction of former Uber Chief Security Officer Joseph Sullivan may pose a chilling reassessment of how chief information security officers (CISOs) and the security community handle network breaches going forward.

A San Francisco federal jury on Oct 5. convicted Sullivan of failing to tell U.S. authorities about a 2016 hack of Uber’s databases. Judge William H. Orrick did not set a date for sentencing.

Sullivan’s lawyer, David Angeli, said after the verdict’s announcement that his client’s sole focus was to ensure the safety of people’s personal digital data.

Federal prosecutors noted that the case should serve as a warning to companies about how they comply with federal regulations when handling their network breaches.

Officials charged Sullivan with working to hide the data breach from U.S. regulators and the Federal Trade Commission, adding his actions attempted to prevent the hackers from being caught.

At the time, the FTC was already investigating Uber following a 2014 hack. The repeat hack into Uber’s network two years later involved the hackers emailing Sullivan about their stealing a large amount of data. According to the U.S. Department of Justice, they promised to delete the data if Uber paid their ransom.

The conviction is a significant precedent that has already sent shockwaves through the CISO community. It highlights the personal liability involved in being a CISO in a dynamic policy, legal, and attacker environment, noted Casey Ellis, founder and CTO at Bugcrowd, a crowdsourced cybersecurity platform.

“It begs for clearer policy at the federal level in the United States around privacy protections and the treatment of user data, and it emphasizes the fact that a proactive approach to handling vulnerability information, rather than the reactive approach taken here, is a key component of resilience for organizations, their security teams, and their shareholders,” he told TechNewsWorld.

Troublesome Details

A growing trend is for companies victimized by ransomware to negotiate with hackers. But trial discourse showed prosecutors reminding companies to “Do the right thing,” according to media accounts.

According to published trial accounts, Sullivan’s staff confirmed the extensive data theft. It included 57 million Uber users’ stolen records and 600,000 driver’s license numbers.

The DoJ reported that Sullivan sought the hackers’ agreement to be paid U.S. $100,000 in bitcoin. That agreement included hackers signing a non-disclosure agreement to keep the hack from public knowledge. Uber allegedly hid the true nature of the payment as a bug bounty.

Subscribe to the TechNewsWorld Newsletter

Only the jury had access to the evidence of the case, so pontificating specific details of the matter is counterproductive, opined Rick Holland, chief information security officer and vice president of strategy at Digital Shadows, a provider of digital risk management solutions.

“There are some general conclusions to draw. I am concerned with the unintended consequences of this case,” Holland told TechNewsWorld. “CISOs already have a challenging job, and the case outcome raises the stakes for CISO scapegoating.”

Critical Unanswered Questions

Holland’s concerns include how this trial’s outcome might impact the number of leaders willing to take on the potential personal liability of the CISO role. He also worries about dislodging more whistleblower cases like the ones that grew out of Twitter.

He expects more CISOs to negotiate Directors and Officers insurance into their employment contracts. That type of policy offers personal liability coverage for decisions and actions the CISO might take, he explained.

“In addition, in the same way that both the CEO and CFO became responsible for corruption on the heels of Sarbanes Oxley and the Enron scandal, CISOs should not be the only roles guilty in the event of wrongdoing around intrusions and breaches,” he suggested.

The Sarbanes-Oxley Act of 2002 is a federal law that established comprehensive auditing and financial regulations for public companies. The Enron scandal, a series of events involving dubious accounting practices, resulted in the bankruptcy of the energy, commodities, and services company Enron Corporation and the dissolution of the accounting firm Arthur Andersen.

“CISOs must effectively communicate risks to the company’s leadership team but should not be solely responsible for cyber security risks,” he said.

Twisted Circumstances

Sullivan’s conviction is an ironic role reversal of sorts. Earlier in his law career, he prosecuted cybercrime cases for the United States Attorney’s Office in San Francisco.

The DoJ’s case against Sullivan hinged on obstructing justice and acting to conceal a felony from authorities. The resulting conviction could have a long-term impact on how organizations and individual executives approach cyber incident response, particularly where it involves extortion.

Prosecutors argued that Sullivan actively concealed a massive data breach. The jury agreed unanimously with the charge beyond a reasonable doubt.

Instead of reporting the breach, the jury found that Sullivan, backed by the knowledge and approval of Uber’s then-CEO, paid the hackers and had them sign a non-disclosure agreement that falsely claimed that they had not stolen data from Uber.

A new chief executive who later joined the company reported the incident to the FTC. Current and former Uber executives, lawyers, and others testified for the government.

Edward McAndrew, an attorney at BakerHostetler and a former DoJ cybercrime prosecutor and National Security Cyber Specialist, told TechNewsWorld that “Sullivan’s prosecution and now conviction is groundbreaking, but it needs to be understood in its proper factual and legal context.”

The government recently adopted a much more aggressive policy toward cybersecurity, he noted. This impacts white-collar compliance, where organizations and executives are increasingly cast into the simultaneous and disparate roles of crime victim and enforcement target.

“Organizations need to understand how the actions of individual employees can expose them and others to the criminal justice process. And information security professionals need to understand how to avoid becoming personally liable for actions they take in responding to criminal cyberattacks,” McAndrew cautioned.

Tags: breach Chief Coverup Data guilty Security Uber

Continue Reading

Previous: Drivers Are Confused About Motor Vehicle Automation
Next: Killing Twitter, With Tesla as Collateral Damage [Opinion]

Related Stories

Qualcomm-Snapdragon-4s-Gen2.jpg New Qualcomm Chip Set To Supercharge Affordable 5G Phones 5 min read
  • NEWS

New Qualcomm Chip Set To Supercharge Affordable 5G Phones

reading-online.jpg ‘Pink Slime’ Websites Outnumber Daily Newspapers on the Internet 5 min read
  • NEWS

‘Pink Slime’ Websites Outnumber Daily Newspapers on the Internet

Apple-Intelligence-WWDC24.jpg Apple Goes All-In on a Privacy-Based AI Experience 5 min read
  • NEWS

Apple Goes All-In on a Privacy-Based AI Experience

Tim-Cook-WWDC24.jpg Apple Outdoes Google and Microsoft in AI Rollout 6 min read
  • NEWS

Apple Outdoes Google and Microsoft in AI Rollout

ewaste-computers.jpg Windows 10 End of Life Could Bury Landfills in E-Waste 5 min read
  • NEWS

Windows 10 End of Life Could Bury Landfills in E-Waste

CopilotPC.jpg The Copilot+ PCs Have Arrived: Initial Impressions 6 min read
  • NEWS

The Copilot+ PCs Have Arrived: Initial Impressions

AFTK Social

  • Facebook
  • Twitter
  • Instagram
  • Youtube
  • VK
  • Whatsapp
  • Latest
  • Popular
  • Trending
  • best-budget-laptops-1.jpg Best laptops 2025: Premium, budget, gaming, 2-in-1, and more
    • Editor's Choice

    Best laptops 2025: Premium, budget, gaming, 2-in-1, and more

  • MS-Project.jpg If you’re working with complex projects, this $15 app makes them much simpler
    • Editor's Choice

    If you’re working with complex projects, this $15 app makes them much simpler

  • Netflix-Hintergrund-1.jpg Best VPN for streaming Netflix 2025: Best overall, cheap, free, and for travelers
    • Editor's Choice

    Best VPN for streaming Netflix 2025: Best overall, cheap, free, and for travelers

  • KDE-Plasma-Desktop-screenshot-promo-1.jpg Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead
    • Editor's Choice

    Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead

  • snipping_tool_in_windows-1.jpg Windows 11’s Snipping Tool now creates DIY animated GIFs
    • Editor's Choice

    Windows 11’s Snipping Tool now creates DIY animated GIFs

  • best-budget-laptops-1.jpg Best laptops 2025: Premium, budget, gaming, 2-in-1, and more
    • Editor's Choice

    Best laptops 2025: Premium, budget, gaming, 2-in-1, and more

  • Meet Jo Jo, Body Positive Model and Cousin of Gigi
    • Headlines

    Meet Jo Jo, Body Positive Model and Cousin of Gigi

  • Finland’s Down’s model Maija makes strides on catwalk
    • Headlines

    Finland’s Down’s model Maija makes strides on catwalk

  • How to Create Adjustment Layers Based on Color
    • NEWS

    How to Create Adjustment Layers Based on Color

  • If You Have $5, Zendaya Found the Spring Collections
    • NEWS

    If You Have $5, Zendaya Found the Spring Collections

  • 5e90465d671ab.jpg Facebook plugs booming business version into Portal
    • ACCESSORIES

    Facebook plugs booming business version into Portal

  • 5e904636599e6.jpg Sony's PlayStation 5 launch set for late 2020
    • ACCESSORIES

    Sony's PlayStation 5 launch set for late 2020

  • 5e90460c39823.jpg Epic Games sued for not warning parents 'Fortnite' is allegedly as addictive as cocaine
    • ACCESSORIES

    Epic Games sued for not warning parents 'Fortnite' is allegedly as addictive as cocaine

  • 5e90459eaad1d.jpg Boeing reports another big drop in deliveries in 3Q
    • ACCESSORIES

    Boeing reports another big drop in deliveries in 3Q

  • 5e90457922df5.jpg New approach for modern power grids that increases efficiency, reduces cost
    • ACCESSORIES

    New approach for modern power grids that increases efficiency, reduces cost

Protect your privacy

Tech News List

Qualcomm-Snapdragon-4s-Gen2.jpg 5 min read New Qualcomm Chip Set To Supercharge Affordable 5G Phones
  • NEWS

New Qualcomm Chip Set To Supercharge Affordable 5G Phones

reading-online.jpg 5 min read ‘Pink Slime’ Websites Outnumber Daily Newspapers on the Internet
  • NEWS

‘Pink Slime’ Websites Outnumber Daily Newspapers on the Internet

Apple-Intelligence-WWDC24.jpg 5 min read Apple Goes All-In on a Privacy-Based AI Experience
  • NEWS

Apple Goes All-In on a Privacy-Based AI Experience

Tim-Cook-WWDC24.jpg 6 min read Apple Outdoes Google and Microsoft in AI Rollout
  • NEWS

Apple Outdoes Google and Microsoft in AI Rollout

ewaste-computers.jpg 5 min read Windows 10 End of Life Could Bury Landfills in E-Waste
  • NEWS

Windows 10 End of Life Could Bury Landfills in E-Waste

Categories

  • ACCESSORIES
  • APPS
  • DAILY TIPS
  • Editor's Choice
  • Headlines
  • HOW TOS
  • INSIDER
  • NEWS
  • PODCAST

Recent Posts

  • Best laptops 2025: Premium, budget, gaming, 2-in-1, and more
  • If you’re working with complex projects, this $15 app makes them much simpler
  • Best VPN for streaming Netflix 2025: Best overall, cheap, free, and for travelers
  • Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead
  • Windows 11’s Snipping Tool now creates DIY animated GIFs

You may have missed

best-budget-laptops-1.jpg Best laptops 2025: Premium, budget, gaming, 2-in-1, and more 14 min read
  • Editor's Choice

Best laptops 2025: Premium, budget, gaming, 2-in-1, and more

MS-Project.jpg If you’re working with complex projects, this $15 app makes them much simpler 1 min read
  • Editor's Choice

If you’re working with complex projects, this $15 app makes them much simpler

Netflix-Hintergrund-1.jpg Best VPN for streaming Netflix 2025: Best overall, cheap, free, and for travelers 14 min read
  • Editor's Choice

Best VPN for streaming Netflix 2025: Best overall, cheap, free, and for travelers

KDE-Plasma-Desktop-screenshot-promo-1.jpg Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead 2 min read
  • Editor's Choice

Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead

Recent Posts

  • Best laptops 2025: Premium, budget, gaming, 2-in-1, and more
  • If you’re working with complex projects, this $15 app makes them much simpler
  • Best VPN for streaming Netflix 2025: Best overall, cheap, free, and for travelers
  • Don’t toss your Windows 10 PC! Try switching to KDE Plasma instead
  • Windows 11’s Snipping Tool now creates DIY animated GIFs
  • Hundreds of Minecraft mods on GitHub are infested with hard-to-spot spyware
  • This 1440p OLED gaming monitor is just $500 today
  • Best budget gaming laptops 2025: Top affordable picks for performance
  • Airrobo PC10 robotic pool cleaner review: An effective low-budget cleaning option
  • Intel teases huge leaps for 18A, the tech behind its next-gen CPUs

Search

Tags

AI Air App Apple Apps artificial Battery Beta Boeing Data Disable Download Enable EU Facebook FaceTime Fix Free gaming Google iOS iPad iPhone Laptop Mac MacOS Media Microsoft Mode Mojave Pro Released Researchers Screen Social Store Surface Tech Testing Tips top Update Video Windows world

Tech Gallery

  • Home
  • About
  • Blog
  • Contact
  • Facebook
  • Twitter
  • Instagram
  • Youtube
  • VK
  • Whatsapp
Copyright © All rights reserved. | WPfastworld