October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Former Uber CSO Joe Sullivan and lessons from the 2016 Uber breach

The 2016 Uber breach exposed data linked to about 57 million users and drivers. Here is how attackers got in, how Joe Sullivan handled the incident according to DOJ trial evidence, the resulting conviction and settlements, and practical security lessons.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The 2016 Uber breach exposed data tied to about 57 million drivers and consumers worldwide, including roughly 600,000 driver-license numbers. Attackers used stolen credentials to reach a private source-code repository, obtained a private access key, and copied user and driver data. The handling of that incident led to former chief security officer Joe Sullivan’s conviction on two federal felonies, three years of probation and a $50,000 fine.

The case is a warning that paying an attacker does not resolve a data breach. A company must preserve evidence, escalate the incident, meet regulator-facing duties and communicate accurately with executives, counsel, regulators and affected people.

What happened in the 2016 Uber breach?

Attackers turned stolen credentials into access to Uber’s code and data

According to the U.S. Department of Justice (DOJ), the attackers used stolen credentials to enter a private source-code repository. They found a private access key there and used it to access and copy data associated with Uber users and drivers. The DOJ describes this access path in its account of the company’s corporate resolution: Uber Enters Non-Prosecution Agreement Related to 2016 Data Breach.

The exposed records included contact details and driver-license numbers

The DOJ’s trial account says approximately 57 million users and drivers were affected, including approximately 600,000 driver-license numbers. Uber’s 2017 disclosure identified names, email addresses and mobile phone numbers among the information downloaded. A later Uber filing describes the same approximate scale worldwide: Uber Form 10-Q for the quarter ended March 31, 2026; the company’s contemporaneous disclosure is 2016 Data Security Incident.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The timing overlapped with an earlier FTC investigation

DOJ says Sullivan learned about the 2016 intrusion 10 days after giving sworn testimony to the Federal Trade Commission in November 2016 about Uber’s security practices. The FTC had been investigating Uber after a separate 2014 breach. That overlap made the company’s treatment of the new incident especially consequential.

How the incident was handled, according to DOJ trial evidence

The following description reflects DOJ’s account of evidence presented at trial, not a separate finding about every factual detail. DOJ said Sullivan arranged a $100,000 bitcoin payment to the hackers in December 2016 and obtained nondisclosure agreements. Those agreements falsely stated that the hackers had not taken or stored data, according to the government’s trial presentation. DOJ also said the incident was withheld from the FTC inquiry.

The FTC later emphasized that Uber’s bug-bounty program was designed for responsible disclosure of security vulnerabilities, not for malicious exploitation. Treating an attacker’s payment as a bounty therefore does not change the underlying fact that consumer information was stolen. The FTC’s revised settlement announcement explains the distinction: Uber Agrees to Expanded Settlement with FTC.

Why Joe Sullivan was convicted

The indictment stage and the trial verdict are different

A superseding indictment announced earlier in the case described wire-fraud and other charges as allegations. An indictment is not a verdict; DOJ’s announcement is here: Former Uber Chief Security Officer To Face Wire Fraud Charges.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In October 2022, a jury found Sullivan guilty of two federal felonies after hearing the government’s evidence about the payment, nondisclosure agreements and the omission from the FTC matter. DOJ’s conviction announcement reports the verdict and the trial evidence: Former Chief Security Officer Of Uber Convicted Of Federal Charges Covering Data Breach.

The sentence

DOJ later reported that Sullivan received three years of probation and a $50,000 fine. The sentencing announcement does not establish a later appellate outcome, so this account does not characterize the judgment as affirmed or reversed: Former Uber Chief Security Officer Sentenced To Three Years’ Probation.

“The message in today’s guilty verdict is clear: companies storing their customers’ data have a responsibility to protect that data and do the right thing when breaches occur,” FBI Special Agent in Charge Robert K. Tripp said in DOJ’s conviction announcement.

Uber’s corporate and regulatory consequences

Public disclosure came in November 2017

Uber disclosed the incident publicly in November 2017. CEO Dara Khosrowshahi wrote, “For that to happen, we have to be honest and transparent as we work to repair our past mistakes.” The company’s disclosure is available at Uber’s 2016 Data Security Incident announcement.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DOJ corporate resolution

Uber entered a non-prosecution agreement with DOJ related to the 2016 breach. That corporate resolution is separate from Sullivan’s individual criminal case and is documented in DOJ’s announcement: Uber Enters Non-Prosecution Agreement Related to 2016 Data Breach.

FTC settlement requirements

In April 2018, the FTC announced an expanded, revised proposed settlement. The agency later announced final approval in October 2018. Keep those stages distinct: the proposal is described at Uber Agrees to Expanded Settlement with FTC, and approval at Federal Trade Commission Gives Final Approval to Settlement with Uber. The settlement framework addressed privacy and security practices, incident response, notification and ongoing assessments.

A $148 million multistate settlement

California announced a nationwide settlement totaling $148 million with Uber over allegations tied to the 2016 breach. The announcement describes commitments involving integrity, security, incident response, notifications and assessments: California Attorney General and San Francisco District Attorney Announce $148 Million Settlement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Operational lessons for companies

1. Treat confirmed theft as an incident, not a bounty interaction

Once evidence shows that an intruder copied customer information, activate the incident-response process. A payment, a confidentiality agreement or a bug-bounty label cannot substitute for containment, legal assessment, evidence preservation and notification analysis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Clarify the security leader’s regulator-facing duties

Written escalation rules should specify who informs the chief executive, board, counsel and regulators when a new incident emerges during an existing inquiry. Sullivan’s discovery of the second breach shortly after sworn FTC testimony shows why those responsibilities cannot remain informal.

3. Preserve truthful records

Incident notes, access logs, chat messages, payment records and agreements should accurately describe what is known and unknown. False language about whether data was taken can create a separate legal problem and undermine later cooperation with regulators.

4. Separate containment from disclosure decisions

Technical responders should contain compromised credentials and repositories while an independent legal and executive group assesses notification duties. Limiting access to evidence and documenting each decision helps prevent a short-term containment choice from becoming concealment.

5. Build a notification and evidence checklist before a crisis

  • Regulator notification: identify the jurisdictions and agencies that may require notice, and record deadlines and decision owners.
  • Affected-user notice: map each exposed data category to the people who may need a clear, accurate explanation.
  • Evidence preservation: secure repository history, identity-provider logs, cloud audit trails, payment records and communications before they are overwritten.
  • Independent oversight: have the board, audit committee or an outside reviewer test whether the incident response and disclosures match the evidence.
  • Post-incident assessment: verify that credentials, keys, repository permissions and monitoring controls were changed, then retain proof of those actions.

A practical response sequence after discovering a similar breach

  1. Contain access. Revoke exposed credentials and private keys, isolate affected repositories and preserve a forensic image of relevant systems.
  2. Establish the facts. Determine what was accessed, copied or merely exposed; identify affected users, drivers and data fields without overstating certainty.
  3. Activate governance. Notify the designated executive, board contact and counsel, and assign one owner for regulator and user communications.
  4. Assess notification duties. Apply the laws and contractual requirements for each affected jurisdiction; document why notice is or is not required.
  5. Communicate accurately. Tell regulators and affected people what happened, what information was involved, what remains unknown and what protective steps are available.
  6. Review independently. Test the response, remediate root causes and preserve the resulting reports for regulators and future audits.

The Uber case does not create a universal response timetable. It does show the cost of treating an incident as a private negotiation when the underlying facts indicate a large-scale theft of personal information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.