Magazine

Former Uber Security Chief Charged for Allegedly Covering up Hack

Posted on the 20 August 2020 by Thiruvenkatam Chinnagounder @tipsclear

The Justice Department has charged Uber's former security chief with covering up a data breach that affected more than 50 million people. While Uber and his then security chief found out about the hack in 2016, the company didn't make it public until a year later, prosecutors said.

Officials said the alleged cover-up came directly from Joe Sullivan, who served as Uber's security chief from April 2015 to November 2017. In October 2016, Uber suffered a data breach by two hackers who were convicted last October, and the online learning website Lynda was also behind cyber attacks.

For more of that

Subscribe to the CNET Now newsletter to receive the most important stories of the day from our editors.

The hackers stole data from 57 million drivers and drivers, including names, email addresses, and driver's license numbers, and agreed to delete them for a price.

Instead of making the hack public - which companies in states like California must do within a certain number of days - Uber paid the hackers $ 100,000 and had them sign a nondisclosure agreement.

Sullivan described the payment as a reward for bug bounty, which companies often pay out to security researchers who identify and discover security flaws. Prosecutors said the payment was more of a cover-up than a bounty reward.

"While this case is an extreme example of a prolonged attempt to undermine law enforcement, we hope companies stand up and get noticed," said Craig Fair, FBI assistant special agent, in a statement. "Don't help criminal hackers cover their tracks. Don't make the problem worse for your customers or cover up criminal attempts to steal people's personal information."

The hack didn't become public for a full year, when former Uber CEO Travis Kalanick was evicted and replaced by Dara Khosrowshahi. Sullivan had informed the new CEO of the cyber attack, but worked out details of what data the hackers had received and when the company paid the hackers.

The company fired Sullivan after the release and paid $ 148 million in one settlement about the data breach.

Sullivan has been charged with obstruction of justice and faces a maximum of five years in prison.

"We continue to cooperate fully with the Justice Department investigation. Our decision in 2017 to disclose the incident was not only the right one, it also embodies the principles by which we conduct our business today: transparency, integrity and accountability." Uber said in a statement.

In private conversations, Sullivan told Uber's security team that court documents said they had to "ensure that the word about the violation is not revealed." The data breach also remained hidden from the Federal Trade Commission, which was investigating Uber for another security concern A data breach that the company suffered in 2014.

The bug bounty payment to Ubers' hackers was characterized by how the company would usually reward security researchers. For starters, Uber's bug bounty program had a cap of $ 10,000 and never paid anything near $ 100,000 according to court documents.

In addition, Uber did not have any rewards for bug bounty with a nondisclosure agreement such as that created for the two hackers. Uber's own bug bounty policy also stipulated that the company would not pay out data dumps from its servers.

"Silicon Valley is not the Wild West," said US attorney David Anderson. "We expect good corporate citizenship. We expect criminal behavior to be reported quickly. We expect cooperation in our investigations. We will not tolerate corporate cover-ups."


Back to Featured Articles on Logo Paperblog