The trial of former Uber Chief Security Officer Joe Sullivan begins this week over allegedly covering up a 2020 data breach and paying off the hackers
Joe Sullivan, Uber's former chief of security, faces criminal charges for his handling of a 2016 security breach. His trial this week has divided the security industry.
Context & Ripple Effects
The case traces back to the 2020 obstruction charge alleging Sullivan concealed the 2016 breach of millions of users' and drivers' records from FTC officials, and to June's ruling that he must also face wire fraud charges over the alleged hush payment to hackers. With the trial now underway, his lawyers are arguing Uber scapegoated him in the aftermath of Travis Kalanick's turbulent exit — putting the company's own breach-handling culture on trial alongside its former security chief.
Why it matters beyond the courtroom: security chiefs across the industry have framed the case as a test of criminal penalties for gray-area disclosure decisions, and a jury later convicted Sullivan for failing to disclose the breach to regulators — a verdict that converts that abstract worry into settled precedent.
First-order effects
- Sullivan personally faces obstruction and wire fraud counts for the decision to pay the hackers and keep the 2016 breach from FTC officials — the first time a CSO's disclosure judgment is tested as a crime rather than a compliance failure.
- Uber's post-Kalanick leadership is directly implicated by the scapegoating defense, which argues the company let its former security chief absorb blame for a breach handled under prior management.
Second-order effects
- CSOs watching the trial will push breach-disclosure decisions up to legal counsel and boards, since Sullivan's prosecution signals that the security chief's signature alone can carry criminal exposure.
- Companies negotiating with hackers now face a documented downside to quiet payments: a ransom deal that doubles as evidence of concealment, raising the cost of settling breaches off the books.
Third-order effects
- If the guilty verdict stands as the template, breach disclosure to regulators becomes a personal-liability decision for named executives, reshaping who signs off on incident response across the industry.
- The case points toward formalized disclosure protocols — legal review, documented regulator contact, board notification — replacing the ad-hoc executive judgment that Sullivan's defense says the gray zone used to permit.
The trend: Data-breach handling is shifting from a corporate compliance matter to a source of personal criminal liability for security executives, with the Sullivan verdict as its defining test.