AP

Former Uber security chief guilty of data breach coverup

Oct 5, 2022, 8:02 PM | Updated: Oct 7, 2022, 2:25 am

SAN FRANCISCO (AP) — The former chief security officer for Uber was convicted Wednesday of trying to cover up a 2016 data breach in which hackers accessed tens of millions of customer records from the ride-hailing service.

A federal jury in San Francisco convicted Joseph Sullivan of obstructing justice and concealing knowledge that a federal felony had been committed, federal prosecutors said.

Sullivan remains free on bond pending sentencing and could face a total of eight years in prison on the two charges when he is sentenced, prosecutors said.

“Technology companies in the Northern District of California collect and store vast amounts of data from users,” U.S. Attorney Stephanie M. Hinds said in a statement. “We will not tolerate concealment of important information from the public by corporate executives more interested in protecting their reputation and that of their employers than in protecting users.”

It was believed to be the first criminal prosecution of a company executive over a data breach.

A lawyer for Sullivan, David Angeli, took issue with the verdict.

“Mr. Sullivan’s sole focus — in this incident and throughout his distinguished career — has been ensuring the safety of people’s personal data on the internet,” Angeli told the New York Times.

An email to Uber seeking comment on the conviction wasn’t immediately returned.

Sullivan was hired as Uber’s chief security officer in 2015. In November 2016, Sullivan was emailed by hackers, and employees quickly confirmed that they had stolen records on about 57 million users and also 600,000 driver’s license numbers, prosecutors said.

After learning of the breach, Sullivan began a scheme to hide it from the public and the Federal Trade Commission, which had been investigating a smaller 2014 hack, authorities said.

According to the U.S. attorney’s office, Sullivan told subordinates that “the story outside of the security group was to be that ‘this investigation does not exist,'” and arranged to pay the hackers $100,000 in bitcoin in exchange for them signing non-disclosure agreements promising not to reveal the hack. He also never mentioned the breach to Uber lawyers who were involved with the FTC’s inquiry, prosecutors said.

“Sullivan orchestrated these acts despite knowing that the hackers were hacking and extorting other companies as well as Uber,” the U.S. attorney’s office said.

Uber’s new management began investigating the breach in the fall of 2017. Despite Sullivan lying to the new chief executive officer and others, the truth was uncovered and the breach was made public, prosecutors said.

Sullivan was fired along with Craig Clark, an Uber lawyer he had told about the breach. Clark was given immunity by prosecutors and testified against Sullivan.

No other Uber executives were charged in the case.

The hackers pleaded guilty in 2019 to computer fraud conspiracy charges and are awaiting sentencing.

Sullivan was convicted of of obstruction of proceedings of the Federal Trade Commission and misprision of felony, meaning concealing knowledge of a felony from authorities.

Meanwhile, some experts have questioned how much cybersecurity has improved at Uber since the breach.

The company announced last month that all its services were operational following what security professionals called a major data breach, claiming there was no evidence the hacker got access to sensitive user data.

The lone hacker apparently gained access posing as a colleague, tricking an Uber employee into surrendering their credentials. Screenshots the hacker shared with security researchers indicate they obtained full access to the cloud-based systems where Uber stores sensitive customer and financial data.

It is not known how much data the hacker stole or how long they were inside Uber’s network. There was no indication they destroyed data.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Republican presidential candidates, former New Jersey Gov. Chris Christie, left, talking with forme...

Associated Press

The GOP debate field was asked about Trump. But most of the stage’s attacks focused on Nikki Haley

The four Republican presidential candidates debating Wednesday night mostly targeted each other instead of Donald Trump.

38 minutes ago

Law enforcement officers head into the University of Nevada, Las Vegas, campus after reports of an ...

Associated Press

Police say 3 dead, fourth wounded and shooter also dead in University of Nevada, Las Vegas attack

Police said a suspect was found dead Wednesday as officers responded to an active shooter and reports of multiple victims at UNLV.

3 hours ago

President Joe Biden's son, Hunter Biden, leaves after a court appearance, July 26, 2023, in Wilming...

Associated Press

Republicans threaten contempt proceedings if Hunter Biden refuses to appear for deposition

House Republicans are threatening to hold Hunter Biden in contempt if he does not show up this month for a closed-door deposition.

5 hours ago

Sen. Tommy Tuberville, R-Ala., listens to a question during a news conference, March 30, 2022, in W...

Associated Press

Tuberville is ending blockade of most military nominees, clearing way for hundreds to be approved

Sen. Tommy Tuberville announced Tuesday that he's ending his blockade of hundreds of military promotions, following heavy criticism.

1 day ago

An employee works inside the Hanwha Qcells Solar plant on Oct. 16, 2023, in Dalton, Ga. On Tuesday,...

Associated Press

US job openings fall to lowest level since March 2021 as labor market cools

U.S. employers posted 8.7 million job openings in October, the fewest since March 2021, in a sign that hiring is cooling.

1 day ago

Megyn Kelly poses at The Hollywood Reporter's 25th annual Women in Entertainment Breakfast, Dec. 7,...

Associated Press

The fourth GOP debate will be a key moment for the young NewsNation cable network

By airing the fourth Republican presidential debate, NewsNation network will almost certainly reach the largest audience in its history.

1 day ago

Sponsored Articles

...

Desert Institute for Spine Care

Desert Institute for Spine Care (DISC) wants to help Valley residents address back, neck issues through awake spine surgery

As the weather begins to change, those with back issues can no longer rely on the dry heat to aid their backs. That's where DISC comes in.

...

Midwestern University

Midwestern University: innovating Arizona health care education

Midwestern University’s Glendale Campus near Loop 101 and 59th Avenue is an established leader in health care education and one of Arizona’s largest and most valuable health care resources.

...

SCHWARTZ LASER EYE CENTER

Key dates for Arizona sports fans to look forward to this fall

Fall brings new beginnings in different ways for Arizona’s professional sports teams like the Cardinals and Coyotes.

Former Uber security chief guilty of data breach coverup