Uber fires CSO, says in Oct '16 personal info of 50M riders, 7M drivers, including 600K driver's license numbers, stolen; Uber paid hackers $100K to delete data
Company paid hackers $100,000 to delete info, keep quiet — Chief Security Officer Joe Sullivan and another exec ousted
Context & Ripple Effects
This is the second time Uber has disclosed a breach involving drivers' license numbers: the May 2014 database breach exposed up to 50K drivers, and the company's response then was a routine disclosure. The October 2016 incident followed the opposite playbook — a $100K payment to the attackers, NDAs, and a payment disguised as a bug bounty, with reporting attributing the order to Travis Kalanick and CSO Joe Sullivan.
First-order effects
- Joe Sullivan is fired as Chief Security Officer and a second executive is ousted, making personnel the immediate cost of the cover-up decision.
- The disclosure itself triggers legal exposure: New York's attorney general opened an investigation into the $100K payment within hours of the announcement.
Second-order effects
- The regulatory net widens beyond New York — five US state AGs are now investigating, at least three potential class actions are forming on behalf of the 50M riders and 7M drivers whose data was taken, and the FTC has made contact over both the hack and the ransom.
- The 600K exposed driver's license numbers give plaintiffs' lawyers and state investigators a concrete harm to litigate, converting a security failure into a governance scandal centered on who at the top authorized concealment.
Third-order effects
- If the pattern holds, breach concealment becomes a personal-liability issue for named security executives rather than a corporate fine line-item — Sullivan's firing sets the precedent that paying attackers and delaying disclosure can end a CSO's career.
- Regulators' focus on the disguised payment and NDAs points toward stricter mandatory-disclosure enforcement, shrinking the window in which companies can privately settle with hackers instead of notifying users.
The trend: Data-breach handling is shifting from a private cost-of-doing-business calculation toward personally accountable executive decisions policed by state attorneys general.