Uber did not immediately respond to requests for comment.
Sullivan was deposed by the FTC as it investigated a 2014 breach of Uber’s online systems. Ten days after the deposition, he received an email from a hacker who claimed to have found another security vulnerability in its systems.
Sullivan learned that the hacker and an accomplice had downloaded the personal data of about 600,000 Uber drivers and additional personal information associated with 57 million riders and drivers, according to court testimony and documents. The hackers pressured Uber to pay them at least $US100,000 ($153,300).
Sullivan’s team referred them to Uber’s bug bounty program, a way of paying “white hat” researchers to report security vulnerabilities. The program capped payouts at $US10,000, according to court testimony and documents. Sullivan and his team paid the hackers $US100,000 and had them sign a nondisclosure agreement.
During his testimony, one of the hackers, Vasile Mereacre, said he was trying to extort money from Uber.
Uber did not publicly disclose the incident or inform the FTC until a new CEO, Dara Khosrowshahi, joined the company in 2017. The two hackers pleaded guilty to the hack in October 2019.
States typically require companies to disclose breaches if hackers download personal data and a certain number of users are affected. There is no federal law requiring companies or executives to reveal breaches to regulators.
Uber did not publicly disclose the incident or inform the FTC until a new CEO, Dara Khosrowshahi, joined the company in 2017. The two hackers pleaded guilty to the hack in October 2019.Credit:AP
Federal prosecutors argued that Sullivan knew that revealing the new hack would extend the FTC investigation and hurt his reputation and that he concealed the hack from the FTC.
“He took many steps to keep the FTC and others from finding out about it,” Benjamin Kingsley, an assistant US attorney, said during closing arguments on Friday. “This was a deliberate withholding and concealing of information.”
Sullivan did not reveal the 2016 hack to Uber’s general counsel, according to court testimonies and documents. He did discuss the breach with another Uber lawyer, Craig Clark.
Like Sullivan, Clark was fired by Khosrowshahi after the new CEO learned about the details of the breach. Clark was given immunity by federal prosecutors in exchange for testifying against Sullivan.
Clark testified that Sullivan had told the Uber security team that it needed to keep the breach secret and that Sullivan had changed the nondisclosure agreement signed by the hackers to make it falsely seem that the hack was white hat research.
Sullivan said he would discuss the breach with Uber’s “A team” of top executives, according to Clark’s testimony. He shared the matter with only one member of the A team: the CEO at the time, Travis Kalanick. Kalanick approved the $US100,000 payment to the hackers, according to court documents.
Lawyers for Sullivan argued that he had merely been doing his job.
They argued that Sullivan and others had used the bug bounty program and the nondisclosure agreement to prevent user data from being leaked — and to identify the hackers — and that Sullivan had not concealed the incident from the FTC.
Loading
After the trial, one of the jurors, Joel Olson, said that the extensive array of documents presented by the lawyers in the case, including edits to the nondisclosure agreement, made it clear that Sullivan had hidden the breach from authorities. “It was all dated and timed and documented very clearly,” he said.
This article originally appeared in The New York Times.
The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.









Add Category