On October 5, 2022, a federal jury in the Northern District of California convicted former Uber Chief Security Officer Joseph Sullivan of obstructing a federal proceeding and misprision of a felony for his role in deceiving management and the federal government to cover up a 2016 data breach that exposed personally identifiable information (“PII”) of approximately 57 million users, including approximately 600,000 drivers’ license numbers, of the ride-hailing service. Sullivan, a former federal prosecutor, appears to be the first corporate executive criminally prosecuted—let alone convicted—for his response to a data security incident perpetrated by criminals. Sullivan faces a maximum of five years in prison for the obstruction charge, and a maximum three years in prison for the misprision charge.
Uber hired Sullivan as its first Chief Security Officer (“CSO”) following a data breach in September 2014 related to the unauthorized access of approximately 50,000 consumers’ personal information, including their names and drivers’ license numbers. In the wake of the 2014 breach, the Federal Trade Commission (“FTC”) initiated an investigation into Uber’s data security program and practices. As CSO, Sullivan oversaw Uber’s response to federal regulators and provided testimony regarding Uber’s data security practices. During this testimony, Sullivan made specific representations about steps he claimed Uber had taken to keep customer data secure. However, in November 2016—mere days after testifying before the FTC in its ongoing investigation of the 2014 breach—hackers contacted Sullivan to inform him of a vulnerability they had discovered that permitted the extraction of a large volume of Uber’s data. The Company did not disclose the 2016 incident to FTC investigators, and entered into a consent decree with the FTC in August 2016.
- Washington D.C.
- James M. Cole, email@example.com
- Karen A. Popp, firstname.lastname@example.org
- Thomas C. Green, email@example.com
- Jeffrey T. Green, firstname.lastname@example.org
- Frank R. Volpe, email@example.com
- Kristin Graham Koehler, firstname.lastname@example.org
- Colleen M. Lauerman, email@example.com
- Leslie A. Shubert, firstname.lastname@example.org
- Angela M. Xenakis, email@example.com
- Brian P. Morrissey, firstname.lastname@example.org
- Ellen Crisham Pellegrini, email@example.com
- Craig Francis Dukin, firstname.lastname@example.org
- William R. Levi, email@example.com
- Julia G. Mirabella, firstname.lastname@example.org
- Jack W. Pirozzolo, email@example.com
- Doreen M. Rachal, firstname.lastname@example.org
- Los Angeles
- Douglas A. Axel, email@example.com
- Ellyce R. Cooper, firstname.lastname@example.org
- Paige Holden Montgomery, email@example.com
- David A. Silva, firstname.lastname@example.org
- New York
- Timothy J. Treanor, email@example.com
- Michael A. Levy, firstname.lastname@example.org
- Joan M. Loughnane, email@example.com
- Michael D. Mann, firstname.lastname@example.org
- David H. Hoffman, email@example.com
- Daniel D. Rubinstein, firstname.lastname@example.org
- Scott R. Lassar, email@example.com
- Geeta Malhotra, firstname.lastname@example.org
- Joseph R. Dosch, email@example.com
- Daniel C. Craig, firstname.lastname@example.org
- San Francisco
- Dave Anderson, email@example.com
- Brian J. Stretch, firstname.lastname@example.org
- Sheila A.G. Armbrust, email@example.com
- Sara George, firstname.lastname@example.org
- Yuet Ming Tham, ytham@Sidley.com
- Margaret H. Allen, email@example.com
- Shu Min Ho, firstname.lastname@example.org
Senior managing associate Alexander J. Kellermann and associate Connor G. Boehm contributed to this Sidley Update.
Sidley Austin LLP provides this information as a service to clients and other friends for educational purposes only. It should not be construed or relied on as legal advice or to create a lawyer-client relationship. Readers should not act upon this information without seeking advice from professional advisers.
Attorney Advertising—Sidley Austin LLP, One South Dearborn, Chicago, IL 60603. +1 312 853 7000. Sidley and Sidley Austin refer to Sidley Austin LLP and affiliated partnerships, as explained at www.sidley.com/disclaimer.
© Sidley Austin LLP