RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Policy & law

Policy & law / From the archive · 5 October 2022 event · prepared 16 September 2026

A federal jury convicted Uber's ex-security chief over a hidden breach

DOJ and FTC records show Joseph Sullivan concealed a 2016 Uber breach from the regulator investigating an earlier one.

Visual for this record: A federal jury convicted Uber's ex-security chief over a hidden breach
Visual published by ftc.gov, shown for identification of the record. Credit: ftc.gov · source page ↗ Rights: owner-review-pending.

What happened

In 2014, Uber disclosed to the Federal Trade Commission that intruders had accessed roughly 50,000 users' personal information, and the FTC opened an investigation into Uber's data-security practices. Joseph Sullivan joined Uber as Chief Security Officer in 2015 and, according to the FTC's own account of the case, oversaw Uber's response to the agency, including sworn testimony in November 2016 about the company's security program. Ten days after that testimony, Uber was breached again; this time the intruders obtained records on approximately 57 million users and drivers. Rather than reporting the new breach to the FTC, Sullivan arranged a $100,000 payment to the intruders in exchange for signed agreements not to disclose the incident, and, according to the Department of Justice's account of the trial evidence, told a subordinate the matter needed to be concealed. Uber's new management discovered and disclosed the breach in November 2017. A federal jury convicted Sullivan on 5 October 2022 of obstruction of FTC proceedings and misprision of felony. He was sentenced on 5 May 2023 to three years' probation and a $50,000 fine.

Confidence and limits

The verdict and sentence are matters of court record as summarized in DOJ's press releases, and the underlying breach facts are independently corroborated by the FTC's 2018 settlement against Uber. This account does not characterize Sullivan's trial defense or any appellate proceedings beyond the conviction and sentence as recorded; the case continued in the courts after sentencing.

Why it mattered

This was among the first convictions of a company security executive personally for how a breach was handled after the fact rather than for the breach itself. The prosecution's theory rested on timing: Sullivan learned of the second breach while Uber's response to the FTC's active inquiry into the first one was still being negotiated, and the government argued that his subsequent concealment obstructed that specific proceeding. The case put individual security leaders on notice that decisions made under pressure, during an active breach, can carry personal legal exposure distinct from the company's.

Defensive takeaway

Route breach-notification and regulator-disclosure decisions through counsel and a documented process rather than leaving them to an individual executive's informal judgment, particularly while a related regulatory inquiry is already open.

  • Who in your organization has authority to decide whether and when a breach is disclosed to a regulator, and is that decision documented?
  • Would a payment to an intruder in your organization be classified and reported as a security expense, or recognized as something requiring disclosure?
  • Does your incident response plan address what happens if a new incident occurs while an earlier one is still under regulatory review?

The conviction does not establish a general legal duty that did not exist before; it applied existing obstruction and concealment statutes to a specific sequence of decisions. The lesson for a security leader is less about the novelty of the law than about how ordinary it can be for a bad decision made under time pressure to later look, in a courtroom, like a deliberate cover-up.

Defensive takeaway

Route breach-disclosure decisions through counsel and a documented process rather than an individual executive's informal judgment, especially while a related regulatory inquiry is already open.

The conviction and sentence are recorded in DOJ's own press releases, and the underlying 2016 breach and its concealment are independently corroborated by the FTC's 2018 settlement action; this article does not address subsequent appellate proceedings.

Sources & reading trail

Former Chief Security Officer Of Uber Convicted Of Federal Charges For Covering Up Data Breach Involving Millions Of Uber User Records ↗

The jury's verdict on obstruction of FTC proceedings and misprision of felony, and DOJ's account of the concealment conduct.

court-or-regulator-primary · Source published: 5 October 2022 · Retrieved: 16 September 2026

Former Chief Security Officer Of Uber Sentenced To Three Years' Probation For Covering Up Data Breach Involving Millions Of Uber User Records ↗

Records the 5 May 2023 sentence of three years' probation and a $50,000 fine.

court-or-regulator-primary · Source published: 5 May 2023 · Retrieved: 16 September 2026

Uber Agrees to Expanded Settlement with FTC Related to Privacy, Security Claims ↗

Independently corroborates the 2016 breach's scope and Uber's concealment of it from the FTC until November 2017.

court-or-regulator-primary · Source published: 12 April 2018 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.