/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A US federal court jury finds ex-Uber Chief Security Officer Joe Sullivan guilty for not disclosing a 2016 breach of customer and driver records to regulators

A jury found Joe Sullivan, who led security at the ride-hailing company, guilty on two different counts.

New York Times Cade Metz

Context & Ripple Effects

The verdict resolves a case that had moved from obstruction charges over the concealed breach to a judge’s decision that Sullivan had to stand trial on wire-fraud allegations. His defense had argued that Uber made him a scapegoat after Travis Kalanick’s exit, making the jury’s finding a clear rejection of that account.

The case had already drawn attention from security leaders who saw it as a test of personal criminal exposure for CSOs when breach response and regulatory disclosure overlap. The conviction turns that professional concern from a pending legal question into an immediate governance issue.

First-order effects

  • Joe Sullivan is convicted on two counts, creating direct personal liability for Uber’s former security chief over the handling of the 2016 incident.
  • Security executives now have a concrete federal-jury outcome to weigh when deciding how breach findings and regulator communications are documented and escalated.

Second-order effects

  • Companies employing CSOs face greater pressure to define who owns disclosure decisions, because a dispute over whether an executive acted for the company can now carry individual criminal consequences.
  • Boards and legal teams are likely to become more involved in breach-response records and regulator-facing decisions, reducing the latitude of security teams to resolve incidents internally.

Third-order effects

  • If this outcome becomes a durable reference point, cybersecurity leadership shifts further from a purely technical function toward a regulated executive role with explicit personal accountability for disclosure conduct.

The trend: Cybersecurity leaders are being held to more formal accountability for how organizations disclose and govern major security incidents, not only for preventing them.

Discussion

  • @hostilespectrum JD Work on x
    This Uber verdict really is going to destroy CISO positions. If one can brief legal, obtain approval by the CEO, & still be hung out to dry for response actions that a hundred other firms have likely taken with far less structural cover, then there can't be enough $$ to sign on
  • @wbm312 Whitney Merrill on x
    A lot of people are conflating legal issues when discussing the Joe Sullivan/Uber - be careful of the red herrings. It's not about breach notification, it's not about bug bounties—it's about lying to a regulator about information responsive to an open investigation and subpoena.
  • @josephmenn Joseph Meany on x
    Our updated story quotes stunned security pros who had already thought their jobs were nerve-wracking without the threat of prosecution. https://www.washingtonpost.com/ ...
  • @wbm312 Whitney Merrill on x
    Hey CISO! Is your company under investigation and under obligation to turn over responsive documentation related to security practices? No? Then this doesn't affect you. Yes? Don't lie. Be truthful in your documentation and work closely with in house counsel on everything. https:…
  • @marciahofmann Marcia Hofmann on x
    Agreed, though I do have questions about why the feds decided to go after Joe Sullivan alone. Seems to me there could have been at least three potential defendants, but Sullivan was the only person indicted. https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    not in Europe :D paying a “bug bounty” after a hack for stolen PII is not compatible with GDPR for a variety of reasons, so the CEO and legal couldn't sign this kind of thing off. https://twitter.com/...
  • @eliomen @eliomen on x
    Lotta CISOs rethinking their career decisions right now. https://twitter.com/...
  • @skupor Scott Kupor on x
    Wow! Personal liability for an approved corporate action (through legal and the CEO)?? https://www.washingtonpost.com/ ...
  • @arekfurt @arekfurt on x
    If you're a CISO and you're worried the Sullivan case might put a chill on future efforts to conceal thefts of customer data from coming to the knowledge of said customers, uh... Well, yes. That's almost certainly a kind of wrongdoing the feds are trying to deter here. 🤷
  • @emilygorcenski @emilygorcenski on x
    Yeesh this is not great https://zpr.io/...
  • @wbm312 Whitney Merrill on x
    The press coverage on the Joe Sullivan/Uber outcome is driving me nuts. They're sinking their teeth into a bunch of red herring issues that will drive panic in the security community. https://twitter.com/...
  • @arekfurt @arekfurt on x
    Former Uber CISO Joe Sullivan has been convicted. As expected. Given that he's a former federal prosecutor, my first guess would be that a federal judge won't be too inclined toward leniency at sentencing. He betrayed the law. And his oath.
  • @hackingbutlegal @hackingbutlegal on x
    “You mean we can be lumped in with corporate bad guys if we do bad things?” -Infosec https://twitter.com/...
  • @dcuthbert Daniel Cuthbert on x
    Maybe this is the stick we needed? No more hiding breaches, which frankly happens too often https://twitter.com/...
  • @carnage4life Dare Obasanjo on x
    People keep taking the wrong lesson away from the Uber CISO case. The primary lesson is not to mislead FTC regulators when they're investigating you. The main company that has to worry about this next is Twitter if Mudge's allegations turn out to be true. https://twitter.com/...