Skip to main content
White Collar: Government Litigation and Investigations, and Privacy and Cybersecurity Update

Uber Data Breach Results in Corporate Cooperation and Executive Conviction

October 10, 2022

On October 5, 2022, a federal jury in the Northern District of California convicted former Uber Chief Security Officer Joseph Sullivan of obstructing a federal proceeding and misprision of a felony for his role in deceiving management and the federal government to cover up a 2016 data breach that exposed personally identifiable information (“PII”) of approximately 57 million users, including approximately 600,000 drivers’ license numbers, of the ride-hailing service. Sullivan, a former federal prosecutor, appears to be the first corporate executive criminally prosecuted—let alone convicted—for his response to a data security incident perpetrated by criminals. Sullivan faces a maximum of five years in prison for the obstruction charge, and a maximum three years in prison for the misprision charge.

Uber hired Sullivan as its first Chief Security Officer (“CSO”) following a data breach in September 2014 related to the unauthorized access of approximately 50,000 consumers’ personal information, including their names and drivers’ license numbers. In the wake of the 2014 breach, the Federal Trade Commission (“FTC”) initiated an investigation into Uber’s data security program and practices. As CSO, Sullivan oversaw Uber’s response to federal regulators and provided testimony regarding Uber’s data security practices. During this testimony, Sullivan made specific representations about steps he claimed Uber had taken to keep customer data secure. However, in November 2016—mere days after testifying before the FTC in its ongoing investigation of the 2014 breach—hackers contacted Sullivan to inform him of a vulnerability they had discovered that permitted the extraction of a large volume of Uber’s data. The Company did not disclose the 2016 incident to FTC investigators, and entered into a consent decree with the FTC in August 2016.

 
Contacts
Sidley’s White Collar practice spans the globe and is consistently recognized as a leader for criminal investigations, agency enforcement actions, False Claims Act matters, and other governmental inquiries and litigation. If you have questions regarding this Update, please contact the Sidley lawyer with whom you work, one of our Privacy and Cybersecurity partners or counsel, or one of our White Collar partners or counsel:
Washington D.C.
Boston
Los Angeles
Dallas
New York
Chicago
San Francisco
London
Singapore

Senior managing associate Alexander J. Kellermann and associate Connor G. Boehm contributed to this Sidley Update.

律师广告—Sidley Austin LLP 是一家全球性律师事务所。我们的地址及联系方式可在 www.sidley.com/en/locations/offices 查阅。

Sidley 提供本信息仅作为向客户及其他友好人士提供的服务,且仅供教育目的使用。本信息不应被解释或依赖为法律意见,亦不构成律师与客户关系。读者在未寻求专业顾问意见之前,不应依据本信息采取任何行动。Sidley 和 Sidley Austin 指 Sidley Austin LLP 及其关联合伙实体,详见 www.sidley.com/disclaimer

© Sidley Austin LLP