Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Former Uber chief security officer Joe Sullivan’s central lesson after his 2022 conviction was that the company should have brought in independent investigators and counsel to review its response to a 2016 data breach. A federal jury convicted him of obstruction of an Federal Trade Commission proceeding and misprision of a felony; in May 2023, he received three years’ probation, 200 hours of community service and a $50,000 fine, with no prison term. His case raises a consequential question for security leaders: when can an executive’s handling of a breach become a personal legal matter?
Sullivan made his comments in a November 2023 interview, comparing his case with the SEC’s then-pending civil action against SolarWinds and its security chief. That comparison was his interpretation, not a finding that the cases were legally alike. The SEC dismissed the SolarWinds action with prejudice in November 2025, a development that changes how the comparison should be understood today.
Who is Joe Sullivan?
Sullivan was Uber’s chief security officer (CSO). Industry coverage often calls the role a chief information security officer (CISO), but the Justice Department used “chief security officer” for his Uber title. He joined Uber in 2015 and had a prominent role in the company’s response to an earlier breach and the resulting Federal Trade Commission (FTC) inquiry.
In November 2016, Sullivan testified under oath to the FTC about Uber’s security practices. About 10 days later, hackers contacted him claiming they had stolen Uber data. The timing mattered: the incident arose while the company was under an active FTC investigation, and the government’s criminal case focused on alleged concealment of the new breach from that proceeding and others.
#1 Best Overall
Uber’s breach and the criminal case: a timeline
| Date | What happened |
|---|---|
| 2014 | Uber experienced an earlier breach involving about 50,000 consumers’ personal information. The FTC later investigated the company’s security practices. |
| November 2016 | Sullivan testified under oath to the FTC. About 10 days later, hackers reported that they had stolen Uber data. Uber personnel verified the incident. |
| 2016 response | According to the government, the hackers used stolen credentials to access a private source-code repository and obtain an access key that enabled them to reach Uber data. The exposed information concerned approximately 57 million users and drivers, including about 600,000 drivers’ license numbers. Uber paid the hackers $100,000 in bitcoin and used nondisclosure agreements. The incident was not disclosed to the FTC at the time. |
| November 2017 | New Uber management investigated and publicly disclosed the breach. The company also reported it to regulators. |
| August 2020 | Federal prosecutors charged Sullivan over his handling of the breach. |
| October 5, 2022 | A federal jury convicted Sullivan of obstruction of an FTC proceeding and misprision of a felony. |
| May 4, 2023 | A judge sentenced Sullivan to three years’ probation, 200 hours of community service and a $50,000 fine. |
| October 30, 2023 | The SEC filed civil charges against SolarWinds and its CISO, Timothy Brown. |
| November 28, 2023 | Sullivan discussed the Uber case and SolarWinds in a Dark Reading interview. |
| November 20, 2025 | The SEC dismissed its SolarWinds action with prejudice. |
The Justice Department’s accounts describe the 2016 incident as affecting approximately 57 million users and drivers—not simply “50 million records.” The two Uber breaches should also be kept distinct: the 2014 incident led to the FTC investigation; the 2016 breach occurred while that inquiry was underway. The DOJ’s conviction release and its Uber resolution describe the government’s account of the breach and response.
What Sullivan said—and what the conviction established
In his 2023 interview, Sullivan said Uber’s response team followed its existing incident-response playbook. He described involving counsel, public relations, the CEO, directors-and-officers insurance and a breach-response policy. He said the failure, in retrospect, was not bringing in independent outside investigators and counsel to validate the team’s assumptions and disclosure decisions. He also advocated greater transparency and said he supported more consistent cybersecurity disclosure requirements.
Rank #2
Those are Sullivan’s retrospective views, not an impartial reconstruction of every disputed fact. The government’s trial account said he concealed the breach from Uber’s lawyers and the FTC, and characterized the hacker payment and nondisclosure agreements as part of that concealment. A jury convicted him of obstruction and misprision of a felony—knowledge of a felony combined with affirmative steps to conceal it. The DOJ’s release identifies those offenses; describing them simply as “fraud charges” is imprecise.
Sullivan said he had remained publicly silent for more than six years on legal advice. He also viewed the sentence as vindicating his account of the broader response. That characterization belongs to him: avoiding prison was a substantially different outcome from the sentence prosecutors sought, but it did not erase his felony convictions. The DOJ sentencing announcement sets out the sentence.
Rank #3
Why Sullivan compared Uber with SolarWinds
When Sullivan spoke in 2023, the SEC had recently accused SolarWinds and CISO Timothy Brown of misleading investors about the company’s cybersecurity. The SEC complaint alleged that SolarWinds overstated its security practices, understated or omitted known risks and vulnerabilities, relied on generic or hypothetical risk disclosures despite allegedly knowing of specific weaknesses, and failed to maintain adequate cybersecurity-related internal controls. It also alleged Brown knew about weaknesses and did not adequately escalate or resolve them. These were allegations in a civil complaint, not findings after trial. The SEC’s charging announcement summarizes them.
Sullivan saw a shared theme: authorities, in his view, trying to hold an individual security leader responsible for a company’s broader communications and disclosure posture. But the legal theories and contexts were different:
Rank #4
| Uber and Sullivan | SolarWinds and Brown | |
|---|---|---|
| Authority and type of case | DOJ criminal prosecution arising from conduct connected to an FTC proceeding | SEC civil enforcement action involving public-company disclosures and internal controls |
| Core conduct alleged | Concealment of a known breach while the FTC was investigating Uber | Misleading cybersecurity statements and inadequate internal controls, as alleged by the SEC |
| Individual exposure | Criminal conviction and sentence | Civil claims against a CISO; the action was later dismissed |
| Current status | Sullivan was convicted and sentenced | The SEC dismissed its action with prejudice on November 20, 2025 |
In November 2025, the SEC announced that it dismissed its civil action against SolarWinds and Brown with prejudice, “in the exercise of its discretion.” The SEC said that the dismissal did not necessarily reflect its position on another case. Dismissal ended that action; it was not a trial verdict establishing that the original allegations were either true or false. The SEC’s dismissal notice explains the disposition.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What the SEC’s cybersecurity disclosure rules require
The SEC’s rules apply to public companies’ investor disclosures; they are not a general law requiring every organization to report every cyber incident. For a public company, a material cybersecurity incident generally must be reported on Form 8-K within four business days after the company determines that the incident is material. The clock does not necessarily start when an intrusion is first detected. The filing describes the incident’s nature, scope and timing and its material or reasonably likely material impact.
Best Value
Annual disclosures address material cybersecurity risk management, strategy and governance, including board oversight and management’s role and expertise. Foreign private issuers generally use Form 6-K for material incident disclosures and Form 20-F for annual disclosures. A narrow delay is available when the U.S. attorney general determines that immediate disclosure would pose a substantial risk to national security or public safety. The SEC’s 2023 rule announcement explains the requirements and timing.
Materiality is not the same as a technical severity rating. A severe intrusion may not be material to investors, while a smaller incident can be material because of its effects on operations, revenue, customers, litigation or other business risks. An investigation may still be incomplete when a disclosure decision is needed; uncertainty should be made clear rather than treated as a reason to ignore the decision. SEC investor reporting also does not replace state breach-notification laws, sector-specific rules, privacy obligations or contractual notice duties.
A practical response framework for CISOs
- Escalate early and broadly. Bring together security, legal, privacy, compliance, executive leadership and communications. Involve the board when the incident or its potential effects warrant it. The CISO should provide technical facts but should not be the company’s sole disclosure decision-maker.
- Use independent review when stakes are high. Sullivan’s stated lesson was to obtain outside investigators and counsel to challenge the internal team’s assumptions. An independent review can improve scrutiny and documentation; it does not guarantee immunity from prosecution or regulatory action.
- Separate evidence from conclusions. Record what is confirmed, what remains uncertain, the evidence supporting each assessment and how the investigation is progressing. Keep technical findings distinct from legal conclusions about reporting duties.
- Document decisions and escalation. Preserve who made materiality, notification, remediation and disclosure decisions; what information they had; what alternatives they considered; and when the decisions were revisited. Privilege should support informed decisions, not become a reason to keep facts from authorized decision-makers.
- Keep public security claims aligned with internal knowledge. Review risk statements, certifications and investor communications against known weaknesses and remediation records. SolarWinds illustrates the kind of inconsistency the SEC alleged, although the action was dismissed and those allegations were not adjudicated.
- Do not treat a bug bounty as breach response. A vulnerability-reporting program is for good-faith vulnerability submissions. It is not a substitute for investigating stolen data, preserving evidence, assessing notification duties or escalating a confirmed breach. The DOJ alleged that Uber’s payment and nondisclosure arrangements occurred in a stolen-data context.
- Check insurance and response arrangements before an incident. Review cyber and directors-and-officers policies, including consent requirements, exclusions, cooperation duties and covered response costs, with counsel and an insurance broker. Coverage can help fund a response but does not transfer governance or disclosure responsibility.
These cases do not establish automatic personal liability for CISOs. They do show why role boundaries alone may not protect an executive whom prosecutors or regulators allege personally concealed information, approved misleading statements or failed to escalate known risks. The practical safeguard is a documented, cross-functional process that makes accurate facts available to the people responsible for corporate decisions.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

