By Kevin Brenner | Friday, August 7, 2026
Not Good is not an indictment of the companies it covers. It is a study of the mistakes made inside them by people prone to making them. This edition examines the Uber data breach that turned a routine incident into a federal case.
________________________________________________
The Uber data breach of 2016 became a landmark cybersecurity case — the first time a corporate security chief was criminally convicted for how a data breach was handled.
In November 2016, ten days after Uber’s top security executive testified under oath to the Federal Trade Commission about how the company protected user data, hackers stole the data of 57 million people.
That timing is the whole story.
The executive was Joe Sullivan. He was not a junior analyst who panicked. He had spent eight years as a federal prosecutor, once the first cybercrime prosecutor assigned full-time to Silicon Valley, and had been Chief Security Officer at Facebook. Uber hired him as its first CSO in April 2015. Roughly six years after the November 2016 breach, he became the first corporate executive in the United States criminally convicted for how he handled a data breach.
Companies pay fines. This time, a security chief stood trial.
The Investigation Already Underway
Uber’s problem started in 2014, when attackers used an access key an engineer had left exposed on GitHub to reach an Uber database, taking the names and driver’s license numbers of roughly 50,000 people. The roots of the Uber data breach reach back to this earlier lapse.
Uber disclosed that breach to the FTC, which opened an investigation into the company’s data security practices. In May 2015, the month after Sullivan was hired, the FTC served a Civil Investigative Demand asking, among other things, about any other instances of unauthorized access to user data.
Sullivan was central to the response. He supervised Uber’s answers, and on November 4, 2016, he gave sworn testimony in the FTC’s investigation.
Ten days later, the test arrived.
The Uber Data Breach
On or about November 14, 2016, an anonymous attacker emailed Uber claiming to have breached its systems and demanding a six-figure payout.
The claim was real. Two hackers had used credentials exposed in earlier breaches to log into Uber’s private GitHub repository, found an Amazon Web Services access key sitting in the code, and used it to reach an AWS storage bucket. They downloaded roughly 57 million records, including about 600,000 names paired with driver’s license numbers.
The same failure mode as 2014. A credential left where it should not have been. The company under investigation for a data breach had just suffered a bigger one, through nearly the identical door, in the middle of the investigation.
That was the moment for disclosure. It went the other way.
“This Investigation Does Not Exist”
Sullivan’s instructions to his team were not ambiguous. He told a subordinate they can’t let this get out, that the information had to be “tightly controlled,” and that outside the security group the story was that “this investigation does not exist.”
Then Uber paid. The company routed $100,000 to the hackers through HackerOne, the platform it used to run its “bug bounty” program, in two bitcoin installments in December 2016. In exchange, the hackers signed non-disclosure agreements that promised silence and contained a false line: that they had not taken or stored any data.
A bug bounty is a reward for a researcher who finds a flaw and reports it. What Uber had on its hands was the reverse: two people who stole 57 million records and wanted to be paid to stay quiet. Running that payment through the bounty program gave it a respectable name and changed nothing about what it was.
At the time, CEO Travis Kalanick knew. After Sullivan flagged a “sensitive” matter, Kalanick texted about handling it as a “bug bounty situation.” He was never charged.
Here is what turned a bad decision into a criminal one. Sullivan kept working with the Uber lawyers handling the FTC inquiry, including the General Counsel, and never told them about the breach that was responsive to the agency’s questions. In summer 2017, with his full support, Uber reached a preliminary settlement with the FTC without disclosing the 2016 breach at all.
The Cover-Up Did Not Hold
Two things unwound it.
First, the hackers were not one-time actors. After the Uber payment, Brandon Glover and Vasile Mereacre ran the same playbook against Lynda.com, owned by LinkedIn, and tried to ransom that data too. They were caught. Both pleaded guilty in October 2019 to computer extortion conspiracy, and both later testified against Sullivan.
Paying an extortionist to disappear assumes the extortionist disappears. They rarely do.
Second, the CEO changed. Dara Khosrowshahi took over in August 2017, and that fall his new management began investigating the 2016 breach. Asked what had happened, Sullivan gave a sanitized version, cutting from a draft summary the facts that the hack had involved personal data and a very large volume of user records, and he repeated the deception to the outside lawyers running the internal investigation. It did not survive scrutiny. On November 21, 2017, Khosrowshahi disclosed the breach and apologized for the roughly year-long delay. Sullivan and a senior lawyer on his team were fired.
The Bill
For Uber, the bill came in three parts. The financial fallout from the Uber data breach was substantial.
In September 2018, Uber agreed to pay $148 million to all 50 states and the District of Columbia over its failure to timely notify drivers and regulators of the breach. In October 2018, the FTC finalized an expanded consent order running 20 years, faulting Uber for concealing the 2016 breach during the original investigation. In July 2022, Uber entered a non-prosecution agreement admitting responsibility for its personnel’s failure to report the breach to the FTC.
Then the bill reached an individual.
On October 5, 2022, after a four-week trial before Judge William H. Orrick, a federal jury convicted Sullivan of obstruction of an FTC proceeding under 18 U.S.C. § 1505 and misprision of a felony under § 4.
On May 4, 2023, Judge Orrick sentenced him to three years of probation, 200 hours of community service, and a $50,000 fine. Prosecutors had asked for 15 months in prison. The judge was blunt about why the sentence was lenient, and about what would happen next time. He said Sullivan got a break “because this was just such an unusual one-off,” and warned: “If there are more, people should expect to spend time in custody.” He added: “If I have a similar case tomorrow, even if the defendant had the character of Pope Francis, they would be going to prison.”
The conviction held up. In March 2025, the Ninth Circuit affirmed. Sullivan had argued the NDA retroactively authorized the hackers’ access, so no felony existed to conceal. The court rejected that outright, holding that illegal access “could not be laundered through Uber’s post hoc authorization,” and noting that Sullivan, a former federal prosecutor, knew the conduct was a felony.
The Case That Split the Industry
This is the rare Not Good subject where serious, honest people still disagree about the verdict. That disagreement is worth taking seriously, because the job Sullivan held is genuinely hard. The Uber data breach case divided even seasoned practitioners.
A CISO operates in a largely unregulated, fast-moving environment with few explicit rules, including few clear rules on when and how to disclose an incident. That is not spin. It is how roughly 50 security leaders described the role in a letter to the court, writing that the work “requires us to act nimbly in time-sensitive, high stakes, and often unique situations.” In 2016, the tools Sullivan used were not exotic. Paying a bug bounty, securing a data-deletion assurance, and getting an NDA were recognized parts of the incident-response playbook, and such payments were common at the time.
So the backlash was real and came from inside the profession. Judge Orrick received 186 letters, many from CISOs, warning of a chilling effect and harm to recruitment once personal liability became real. Sullivan’s lawyers argued he was “prosecuted for doing his job,” and singled out among more than 30 co-employees who had the same information.
The fairness critique has force. The CEO knew. A company lawyer was in the loop. Yet the security chief alone stood trial.
Two things keep the lesson intact. First, Judge Orrick, who read all 186 letters, said some of Sullivan’s supporters did not fully understand the facts. Second, Deputy Attorney General Lisa Monaco distinguished this case from ordinary security work: the conduct here involved “intentional acts, as was proved at trial, and very, very different from a mistake made by a CISO or compliance officer in the heat of a very stressful time… This intentional activity, misleading the FTC, has nothing to do with the well-meaning and stressful work that CISOs and compliance officers have to deal with in the heat of the worst day of their lives if they’re undergoing a breach.”
That is the fault line. Had Sullivan been convicted for a defensible, good-faith judgment call in a gray zone, the chilling-effect fear would be justified, and this newsletter would be defending him. That is not what the jury found. It found an NDA with a false representation in it, an instruction that “this investigation does not exist,” a regulator kept in the dark, and a new CEO given a scrubbed summary. None of those are the ambiguity of the role. They are the choices a person makes after the hard call is already behind them.
The job is hard. Concealment is not part of the job.
My Read on the Uber Data Breach
Take the strongest version of the defense seriously, because it is the one that will show up in your own company. The role is under-defined. The pressure is real. The CEO knew, the amount was in a normal range for a bounty, and the security community closed ranks around a respected colleague who felt like the fall guy.
All of that can be true, and the conviction can still be right, because “others were culpable too” is not the lesson. Sullivan was not convicted for being breached, or for paying a bounty, or for the amount. He was convicted because there was a live federal investigation into Uber’s data security, the breach was directly responsive to it, and he took affirmative steps to keep the answer from the people entitled to it. The crime was the concealment, not the incident.
That is the throughline of this newsletter. McKinsey’s criminal exposure did not come from bad advice; it came from a partner deleting documents while litigation risk was obvious. Boeing’s exposure kept returning to what it did not disclose to its regulator. Volkswagen’s problem stopped being a product defect the moment executives kept managing the story after they knew the truth. The underlying problem is usually survivable. The decision to hide it is what gets prosecuted.
There is a second read for anyone who runs security or compliance. Sullivan’s defense, that he used ordinary tools, cuts the other way. A legitimate control was used to do an illegitimate thing. Bending a real control to launder a bad outcome is more dangerous than having no control, because it looks like process. It generates paper that says everything was handled. The label on the payment said the system worked. The substance said the opposite.
How to Avoid Becoming the Next Cautionary Tale
- Treat a live regulatory inquiry as a duty to update, not a snapshot. New facts that answer a regulator’s questions have to move toward the regulator, not away. Build a standing process so anyone who learns something responsive to an open inquiry has a direct, documented path to the people managing it. Silos are not a defense. They are the mechanism.
- Decide who owns breach disclosure before you are breached. Write down, in advance, who makes the notification call, who must be consulted, and who cannot be routed around. A CISO, a GC, and a CEO should never be improvising that division of labor in the 48 hours after a ransom email.
- Do not let a legitimate control launder an illegitimate act. Bug bounty programs, NDAs, and retention policies are real tools. The moment one is being used to make a problem disappear rather than manage it honestly, stop and ask how it reads in a complaint. A $100,000 “bounty” paid to people who exfiltrated 57 million records reads as a payoff no matter what the wire memo says.
- Assume the person you are paying to be quiet will not be. Uber paid two hackers to disappear. They went and hit another company. Every payment becomes its own piece of evidence. Route intrusions to law enforcement and counsel, not to a payment platform.
- Personal liability is now real for the people in the room. The old assumption that the company absorbs the enforcement risk and executives move on is gone for security and compliance leaders. A judge has said on the record that the leniency here was a one-time artifact of being first. The next defendant does not get probation.
- Give your CISO written disclosure authority and air cover. The backlash to this case is really a complaint that security leaders absorb personal liability for decisions made jointly with the CEO and General Counsel. Answer it with structure, not sympathy. Define in writing who holds disclosure authority, guarantee the CISO a direct escalation path to the GC and the board, and make explicit that the security leader’s job is to surface the hard call, not to privately own the legal risk of it. A CISO who can escalate without penalty has no reason to bury anything. The best protection against another Sullivan case is a system where the honest choice is also the safe one.
One More Thing
The Uber data breach remains a defining reference point for security and legal teams. The detail worth sitting with is not the $100,000 or the 57 million records. It is that Joe Sullivan, of all people, made this call. A former federal cybercrime prosecutor. A man who had run security at Facebook. Someone who knew exactly what obstruction and misprision were, and knew a stolen-credential intrusion was a felony.
That is the point of Not Good. The cover-up is rarely the work of someone who does not understand the rules. It is often the work of the person who understands them best and decides, under pressure, that this once the rules can be managed. A bounty payment. An NDA with one false line in it. A settlement signed with one fact left undisclosed.
Spot the red flag now. Or read about it in the next issue.
Click Here to Schedule a 30 minute Consultation with Kevin Brenner
This post is for informational purposes only and does not constitute legal advice. The discussion of this matter, including the conduct of any individuals involved, is based solely on publicly available information and court filings. Nothing in this post should be interpreted as a statement of fact about any person’s character, intentions, or actions beyond what has been reported in official sources.
The analysis provided reflects general legal principles and commentary and may not apply to any specific situation. Reading this post does not create an attorney-client relationship with the author or their firm. If you have questions about how these issues may affect your organization, you should consult qualified legal counsel.
The information provided on this website is for general informational purposes only and should not be considered legal advice. No attorney-client relationship is created by accessing or using this website. Please consult with a qualified attorney before making any legal decisions. Global Link Law is not liable for any reliance on the information provided. Prior results do not guarantee a similar outcome.