The headline says a security chief went down for paying off hackers. Read the docket and a different story appears: the payment counts were dismissed, the punishment was probation, and the man the judge thought equally guilty was never in the room.

Pairs with the Crisis Response Playbook — a ready-to-use strategy tool. Included in the Crisis Response Casebook →

In October 2016, two hackers slipped into an Uber data store and walked out with the personal records of 57 million people — 50 million riders' names, emails, and phone numbers, and about 7 million drivers' details, including roughly 600,000 U.S. driver's license numbers.1 Uber's response was not to warn anyone. It was to find the intruders, pay them $100,000 to delete what they'd taken, and dress the transaction up so it looked like a routine bug-bounty reward.2 The company then said nothing to regulators or to the people whose data was gone for more than a year.9 It is a clean, damning story — and the way it is usually told is wrong in a way that matters.

The popular version is that Uber's security chief was convicted for paying off hackers and hiding a breach. The record says something narrower and stranger. Joe Sullivan was not convicted for the $100,000 payment — the counts built on that were dropped before the jury ever heard them. He was convicted for what he did to one specific reader of that story: a federal investigator who had him under oath ten days before the second hack even surfaced.3 The crime wasn't the payoff. It was lying to the government about a fire while the government was already asking about smoke.

The clock that turned a bad decision into a felony: an FTC investigator was already at the door when the second breach arrived

Here is the timing that makes this case unlike any ordinary cover-up. The Federal Trade Commission was not sniffing around after the 2016 breach; it was already investigating an earlier 2014 Uber breach, and Sullivan — hired soon after that probe opened — had testified to the FTC under oath on November 4, 2016.5 Ten days later, he learned Uber had been hacked again, through the same kind of vulnerability that caused the 2014 incident.5 That ten-day gap is the whole case. A company can make a terrible, even craven, business call about a breach and commit no federal crime. But when an agent of the state has you on the record about your security, and you then withhold the very thing they're investigating, the ordinary bad judgment becomes obstruction of justice.3

10 days
between Sullivan testifying to the FTC under oath and learning of the second breach he then helped conceal — the interval that turned a business decision into a felony5

That is why the charges that actually stuck were 18 U.S.C. § 1505 — obstructing an agency proceeding — and § 4, misprision of a felony: concealing a crime you know about.3 Neither is about the mechanics of the payment. Neither is about hiding the breach from users. Both are about the one audience Uber was legally forbidden to mislead: the regulator already in the room.

The charge everyone remembers was quietly dropped: the $100,000 payoff generated the loudest headlines and the weakest conviction

This is the part the retellings skip. Prosecutors did try to nail Sullivan on the payment. A superseding indictment added three wire-fraud counts tied directly to the $100,000 disguised as a bug-bounty reward.4 Then, shortly before trial, the government agreed to dismiss those very counts. The jury convicted on obstruction and misprision alone.4 The most vivid, most quotable element of the whole affair — a company paying criminals hush money — is the element the conviction does not rest on. The state kept the boring counts and dropped the cinematic ones, because obstruction was the charge it could actually prove.

The popular versionWhat the record shows
The crimePaying hackers, hiding a breachObstructing an active FTC investigation
The wire-fraud counts (the payoff)What he went down forDismissed before trial
The punishmentPrisonThree years' probation and a $50,000 fine
The CEONot in the storyCalled 'just as culpable' — never charged
The story people tell vs. what the verdict actually says

A landmark conviction that ended in community service: the first executive tried for a breach cover-up got no prison time at all

The second distortion is the sentence. This was, by wide agreement, likely the first time a security executive faced criminal charges for mishandling a data breach — a genuine landmark.6 Yet on May 4, 2023, Judge William Orrick handed down three years' probation, 200 hours of community service, and a $50,000 fine.56 Prosecutors had pushed for 15 months of actual incarceration and did not get it.6 For a man who faced years in prison, the outcome was a precedent that lands like a warning shot rather than a body blow. The Ninth Circuit unanimously upheld the conviction in March 2025, so the principle stands — an executive can be criminally liable for how a breach is concealed — but the price attached to that principle, so far, is a résumé stain and some volunteer hours.

just as culpable7
Judge William Orrickon Travis Kalanick, Uber's CEO at the time of the breach — who was never charged

And then the third distortion, the loudest silence in the whole story. The judge who convicted Sullivan said in open court that he believed Kalanick — Uber's CEO at the time, who had allegedly discussed a strategy for handling the breach with Sullivan — was 'just as culpable.'7 Kalanick was never charged. He instead submitted a character letter supporting Sullivan before sentencing, a gesture the judge found notable precisely because Kalanick was neither a defendant nor a trial witness.6 So the person the sentencing judge thought equally guilty appeared in the case only as a reference for the one man who was convicted.

Where the real money went: the company paid a record penalty while the individual paid in reputation

Follow the actual damage and the asymmetry sharpens. Uber tracked the hackers down, extracted assurances the data was deleted, and then waited a full year — until November 2017 — to disclose anything.9 For that delay the company paid a record $148 million to settle with all 50 states and the District of Columbia in September 2018, for violating state breach-notification laws by intentionally concealing the intrusion.8 Texas alone took more than $6.4 million of it.9 The corporate entity absorbed a nine-figure fine; the individual absorbed a felony record and community service; the CEO absorbed nothing. That is the map of accountability this case actually drew.

The Uber breach cover-up — by the numbers
57M
riders and drivers whose data was taken1
$100K
paid to the hackers to delete the data2
$148M
Uber's multistate settlement over the concealment8
3 years
probation for the convicted security chief — no prison5

Isn't a conviction still a conviction?: the precedent is real even if the punishment was mild — and that is the uncomfortable part

The fair objection is that all of this parsing risks trivializing a real conviction. Sullivan was found guilty of two felonies by a jury, and an appeals court unanimously agreed the verdict was sound.10 A security chief is now, undeniably, a person who can go to trial for how a breach is buried — and that alone changes the incentive math for every CISO in the country. True. The precedent is the point, and it is durable. But the honest reading is that the precedent is narrower than the folklore. It does not say 'don't pay ransoms' and it does not say 'don't hide breaches from the public.' It says one thing with force: do not conceal from an investigator who is already investigating you. The line the law drew is not around bad crisis judgment. It is around lying to the government. Sullivan crossed a specific, bright line, at a specific, unlucky moment, ten days after being sworn in as a witness against his own company's future.

The regulator in the room changes everything

Most crisis-response mistakes are civil problems — you disclose late, you pay a fine, the company eats it. What turns a mishandled breach into a personal felony is not the size of the breach or the shape of the payment; it is whether an active investigation is already underway and whether you, personally, are on the record with the people running it. The moment a regulator is asking, the calculus flips: silence stops being a PR decision and becomes obstruction. Uber's mistake wasn't unique. Its timing was. The lesson for anyone running incident response: find out who is already watching before you decide what to say — because concealment from a customer costs money, and concealment from an investigator costs your freedom.

The neat headline says Uber's security chief was convicted for paying off hackers and covering up a breach. Strip it down and almost every load-bearing word is off. He wasn't convicted for the payment — those counts vanished before trial. He wasn't sent to prison — he got probation and a fine. And he wasn't the only culpable party — merely the only charged one. What survives the demolition is a smaller, harder truth: the crime that stuck was not hiding a breach from 57 million people. It was hiding it from the one person already asking. In a cover-up, the audience you fool is a scandal. The audience you fool while they're investigating you is a felony.

Take it with you — Crisis Response
Playbook

Crisis Response Playbook

A playbook for a crisis already in motion: who decides, which plays fire on which trigger, and what gets said to whom. It replaces panic and the all-hands meeting with a pre-agreed sequence each person can run alone. Blank to pre-load before a crisis hits; filled as the worked example reconstructing the plays the story's team ran — and the ones they should have.

Blank template

Included, filled and blank, in the Crisis Response Casebook. See the set → · Preview the blank →

Sources

Where this comes from — the filings, records, and reporting behind it.

  1. 1
    PublishedWidely reported
    Hackers stole personal data of 57 million Uber customers and drivers in an October 2016 attack, comprising 50 million riders' names/emails/phone numbers and about 7 million drivers' data including roughly 600,000 U.S. driver's license numbers; no Social Security numbers, credit card data, or trip-location data were taken. Uber concealed the breach for over a year and fired its chief security officer and a deputy for their roles in keeping the hack under wraps, which included a $100,000 payment to the attackers.
  2. 2
    PublishedWidely reported
    Uber did not report the 2016 incident to regulators or affected customers, but instead paid $100,000 to the hackers to get rid of the data in order to keep the breach under wraps.
  3. 3
    PublishedDocumented
    Joe Sullivan was found guilty on Oct. 5, 2022 of obstruction of justice (18 U.S.C. § 1505) and misprision of a felony (18 U.S.C. § 4); the conviction arose specifically because, ten days after being deposed under oath by the FTC on Nov. 4, 2016 in a pre-existing investigation into a 2014 Uber breach, Sullivan learned of the new 2016 hack affecting more than 57 million riders and drivers and, per the government's allegation, took steps to hide the new incident from the FTC rather than disclose it.
  4. 4
    PublishedWidely reported
    A superseding indictment added three wire-fraud counts tied to the hacker payoff made under the guise of a bug-bounty reward, but prosecutors agreed to dismiss those wire-fraud charges shortly before trial; the jury convicted Sullivan only of obstruction and misprision of a felony. The two hackers responsible pleaded guilty in 2019 to extortion demands against companies including Uber and LinkedIn. Uber's then-CEO Dara Khosrowshahi fired Sullivan and in-house attorney Craig Clark, who had overseen the $100,000 bitcoin payment, in November 2017.
  5. 5
    Primary · Court recordDocumented
    Joseph Sullivan was sentenced to a three-year term of probation and ordered to pay a $50,000 fine by Judge William H. Orrick after a jury found him guilty of two felonies (obstruction of justice and misprision of a felony) in October 2022; the FTC's Division of Privacy and Identity Protection had been investigating a 2014 Uber breach and Sullivan, hired soon after that investigation launched, had testified under oath to the FTC in November 2016 — ten days before learning Uber had been hacked again via the same vulnerability that caused the 2014 breach.
  6. 6
    PublishedWidely reported
    Sullivan was sentenced to three years' probation and 200 hours of community service on May 4, 2023, for covering up the 2016 cyberattack from authorities and obstructing the FTC's federal investigation; prosecutors had pushed for 15 months in prison, and the case is likely the first time a security executive has faced criminal charges for mishandling a data breach. Former Uber CEO Travis Kalanick submitted a letter supporting Sullivan's character ahead of sentencing, which the judge found notable given Kalanick was not charged or a trial participant.
  7. 7
    PublishedAttributed to source
    At sentencing, Judge William Orrick said he believed Travis Kalanick, Uber's CEO at the time of the breach, was 'just as culpable' as Sullivan for the cover-up, though Kalanick was not charged in connection with the intrusion despite allegedly having discussed a strategy for handling the breach with Sullivan.
  8. 8
    Primary · Court recordDocumented
    On September 26, 2018, Uber agreed to pay a record $148 million penalty to settle with all 50 states and the District of Columbia over its handling of the 2016 breach; New York received approximately $5.1 million and Massachusetts received $7.1 million. The settlement found that by intentionally concealing the breach and failing to disclose it for a year, Uber violated state data-breach notification laws (e.g., New York's GBL § 899-aa), and separately resolved allegations tied to an earlier 2016 settlement stemming from a 2014 breach in which a hacker accessed roughly 50,000 drivers' license numbers that Uber also failed to promptly disclose.
  9. 9
    Primary · Court recordDocumented
    Per the Texas Attorney General's settlement announcement, Uber tracked down the two hackers responsible for the November 2016-discovered breach and obtained assurances that they had deleted the information, but failed to report the breach in a timely manner and waited until November 2017 — a full year — to report it or inform affected drivers that their driver's license information had been accessed; Texas received more than $6.4 million of the $148 million multistate settlement.
  10. 10
    PublishedWidely reported
    On March 13, 2025, a three-judge panel of the U.S. Court of Appeals for the Ninth Circuit unanimously upheld Sullivan's 2022 conviction for obstruction of justice and misprision of a felony, confirming that Sullivan obstructed an FTC investigation into Uber's security practices following the 2016 data breach.

More like this — beyond Uber

New Strategically analyses as they publish: the defining moves in business, checked against the record. No noise, and one click to leave.