On 5 October 2022, after a month-long trial, a jury in the Northern District of California convicted Joseph Sullivan, Uber’s former chief security officer, of obstructing a Federal Trade Commission investigation into the company’s data security practices and of misprision of felony.
The charges concerned the concealment of a 2016 intrusion affecting around 57 million passengers and drivers, including approximately 600,000 driver’s licence numbers. Rather than reporting it, $100,000 in bitcoin was paid to the attackers and processed through the company’s bug bounty programme. In May 2023 Sullivan was sentenced to three years’ probation and 200 hours of community service.
We Have Recorded Delay Constantly And Consequence Rarely
This database is substantially a record of intervals: 289 days at 26-0721b, two months at 22-0120, ten months between detection and disclosure at 23-0808b, four months at 22-0404. In almost none of those does anything happen to anyone.
This file is the exception, and it is worth being precise about what it establishes. The conviction was not for the breach, nor for being slow. It was for obstructing a regulator already asking questions, and for concealing a felony. The threshold is much higher than late notification, and nothing here suggests that delay by itself carries jeopardy.
A Legitimate Mechanism, Used As A Channel
A bug bounty programme pays researchers who report flaws. It has an approval path, a budget line and a plausible reason to send money to someone who found a weakness — which is precisely what made it usable for a payment that was not a bounty.
We keep recording systems doing exactly what they were built to do, to bad effect — 22-0417, where a governance vote counted borrowed money; 22-0404, where legitimate access outlived employment. This is the same shape pointed inward: the concealment ran through a control, not around one.
What It Did To The Job
The verdict was read across the profession as establishing personal exposure for security executives, and the sentence — probation, not prison — as tempering it.
The desk records the reaction without endorsing the more dramatic readings. What the case actually demonstrates is narrower and more useful: the person who decides how to characterise an incident to a regulator is making a legal decision, not a technical one, and doing that alone is the hazard. We filed the corporate-side version at 23-1030, where a regulator pursued a company and an officer over security representations.
Compiled from contemporaneous reporting of the trial, verdict and sentencing, and on legal analyses of it, listed below. This desk has not read the trial record. Sullivan is named because he was convicted, per the standard applied at 26-0716b and withheld at 26-0725. Characterisations of what the verdict means for security officers generally are attributed as professional reaction, not carried as findings. Graded high. Corrections: corrections@forensicpost.com.
- Former Uber security chief convicted of covering up 2016 data breachThe Washington Post
- US jury convicts former chief security officer for mishandling cybersecurity breachNorton Rose Fulbright
- Uber ex-CSO verdict raises thorny issues of cyber governance and transparencyCybersecurity Dive