MENU

suburb

  • Loading ...
  • Loading ...

Adelaide Child Care

Latest News Adelaide Child Care

Are you looking for a holiday? Get special deals.

 

Uber’s ex-security chief faces landmark trial over data breach that hit 57m users

09 Sep 2022 By theguardian

Uber’s ex-security chief faces landmark trial over data breach that hit 57m users

Uber's former security officer, Joe Sullivan, is standing trial this week in what is believed to be the first case of an executive facing criminal charges in relation to a data breach.

The US district court in San Francisco will start hearing arguments on whether Sullivan, the former head of security at the ride-share giant, failed to properly disclose a 2016 data breach affecting 57 million Uber riders and drivers around the world.

At a time when reports of ransomware attacks have surged and cybersecurity insurance premiums have risen, the case could set an important precedent regarding the culpability of US security staffers and executives for the way the companies they work for handle cybersecurity incidents.

The breach first came to light in November 2017, when Uber's chief executive, Dara Khosrowshahi, revealed that hackers had gained access to the driver's license numbers of 600,000 US Uber drivers as well as the names, email addresses and phone numbers of as many as 57 million Uber riders and drivers.

Public disclosures like Khosrowshahi's are required by law in many US states, with most regulations mandating that the notification be made "in the most expedient time possible and without unreasonable delay".

But Khosrowshahi's announcement came with an admission: a whole year had passed since the information had been breached.

"You may be asking why we are just talking about this now, a year later," Khosrowshahi said at the time, adding that the company had investigated the delay and had fired two executives who had led the response to the breach, one of whom was Sullivan.

Uber's disclosure sparked several federal and statewide inquiries. In 2018, Uber paid $148m over its failure to disclose the data breach in a nationwide settlement with 50 state attorneys general. In 2019, the two hackers pleaded guilty to hacking Uber and then extorting Uber's "bug bounty" security research program. In 2020, the Department of Justice filed criminal charges against Sullivan.

In court filings, federal prosecutors alleged that in an attempt to cover up the security violation, Sullivan had "instructed his team to keep knowledge of the 2016 Breach tightly controlled" and to treat the incident as part of the bug bounty program.

That program was intended to incentivize hackers and security researchers to report vulnerabilities in exchange for cash rewards, but it did not allow for "rewarding a hacker who had accessed and obtained personally identifiable information of users and drivers from Uber-controlled systems", the complaint says.

The hackers in the 2016 breach were rewarded $100,000, the complaint says, more than any bounty the company had paid as part of the program until that point.

Sullivan also allegedly had the hackers sign a supplemental non-disclosure agreement (NDA) which "falsely represented that the hackers had not obtained or stored any data during their intrusion", federal prosecutors wrote.

In 2018, months after he was fired, Sullivan contested any claims of a cover-up and said he was "surprised and disappointed when those who wanted to portray Uber in a negative light quickly suggested this was a cover-up".

Neither Sullivan nor Uber immediately responded to a request for comment.

The justice department complaint alleged that only Sullivan and the former Uber chief executive Travis Kalanick had knowledge of the full extent of the hack as well as a role in the decision to treat it as an authorized disclosure through the bug bounty program. However, as the New York Times first reported, the security industry is divided over whether Sullivan deserves to be held solely responsible for the breach. Some have questioned whether the role of other company executives and its board should be investigated as well, while others say Sullivan's role in it was clear.

The trial will play out as reports of ransomware attacks continue to rise. In 2021, the US saw a more than 95% increase in ransomware attacks, according to the threat intelligence firm SonicWall. Many of those attackers have targeted healthcare facilities and schools. Hackers targeted the Los Angeles unified school district, the second-largest school district in the US, with a cyber-attack over Labor Day weekend.

More News

Booking.com
Robot with animated face is here to make customer service better
Robot with animated face is here to make customer service better
Fake PayPal email let hackers access computer and bank account
Fake PayPal email let hackers access computer and bank account
Flight passenger brings up 'vaping in the bathroom,' sparking debate about on-board actions
Flight passenger brings up 'vaping in the bathroom,' sparking debate about on-board actions
Mexico rolls back its controversial new tax on cruise ship visitors
Mexico rolls back its controversial new tax on cruise ship visitors
Menendez brothers resentencing: Timeline of killers' fight over freedom in parents' murders
Menendez brothers resentencing: Timeline of killers' fight over freedom in parents' murders
Dwyane Wade casts doubt on legitimacy of NBA Draft Lottery amid rigging speculation: 'It's a business'
Dwyane Wade casts doubt on legitimacy of NBA Draft Lottery amid rigging speculation: 'It's a business'
Schumer, Democrats dodge questions about brutal Biden revelations with 'looking forward' talking point
Schumer, Democrats dodge questions about brutal Biden revelations with 'looking forward' talking point
Indiana high school sports conference facing pressure to end DEI quotas
Indiana high school sports conference facing pressure to end DEI quotas
Trump's influence possible factor in MLB's removal of Pete Rose from ineligible list, ESPN broadcaster says
Trump's influence possible factor in MLB's removal of Pete Rose from ineligible list, ESPN broadcaster says
Caitlin Clark reveals what she and Taylor Swift discussed at Chiefs playoff game
Caitlin Clark reveals what she and Taylor Swift discussed at Chiefs playoff game
Bill Belichick's girlfriend Jordon Hudson says relationship led to 'identity erasure' in letter to cheer team
Bill Belichick's girlfriend Jordon Hudson says relationship led to 'identity erasure' in letter to cheer team
Barstool Sports founder Dave Portnoy, a Celtics fan, gives Knicks star a 'subtle' message in hotel run-in
Barstool Sports founder Dave Portnoy, a Celtics fan, gives Knicks star a 'subtle' message in hotel run-in
Marcus Ericsson knows winning Indy 500 again won't be easy, but he has a secret ingredient
Marcus Ericsson knows winning Indy 500 again won't be easy, but he has a secret ingredient
Draymond Green, 2 technical fouls away from suspension, fined $50,000 for questioning officials' 'integrity'
Draymond Green, 2 technical fouls away from suspension, fined $50,000 for questioning officials' 'integrity'
AI predicts biological age, plus flesh-eating insects pose health risk
AI predicts biological age, plus flesh-eating insects pose health risk
Teacher quits profession after viral rant on how AI is 'ruining' education
Teacher quits profession after viral rant on how AI is 'ruining' education
Zach Bryan feud escalates as John Moreland claims getting kicked off album is 'cooler' than being on it
Zach Bryan feud escalates as John Moreland claims getting kicked off album is 'cooler' than being on it
Jose Mujica, Uruguay's former leader, rebel icon and cannabis reformer, dead at 89
Jose Mujica, Uruguay's former leader, rebel icon and cannabis reformer, dead at 89
ESPN insider suggests massive NFL Draft change before Arch Manning becomes eligible
ESPN insider suggests massive NFL Draft change before Arch Manning becomes eligible
Red state treasurer reveals why state financial officers have 'obligation' to combat ESG, DEI
Red state treasurer reveals why state financial officers have 'obligation' to combat ESG, DEI
Latest News

copyright © 2025 Adelaide Child Care.   All rights reserved.

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z