Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Nominations for the Startup Battlefield 200 are now open

Lucid Motors is cutting 12% of its workforce as it pursues profitability

Peak XV Raises $1.3B, Doubles In AI As Global India VC Competition Heats Up

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Great news for xAI: Grok is now very good at answering questions about Baldur’s Gate

    21 February 2026

    UAE’s G42 partners with Cerebra to deploy 8 exaflops of computers in India

    20 February 2026

    Why these startup CEOs don’t think AI will replace human roles

    20 February 2026

    Reliance unveils $110bn AI investment plan as India boosts tech ambitions

    19 February 2026

    Amazon Terminates Blue Jay Robotics Project After Less Than 6 Months

    19 February 2026
  • Apps

    Remember HQ? “Quiz Daddy” Scott Rogowsky is back with TextSavvy, a daily mobile game show

    21 February 2026

    As the browser war heats up, Chrome is adding new productivity features

    20 February 2026

    Google says its AI systems helped prevent Play Store malware in 2025

    20 February 2026

    Mastodon, a decentralized alternative to X, plans to target creators with new features

    19 February 2026

    Etsy sells used clothing marketplace Depop to eBay for $1.2 billion

    19 February 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    InScope raises $14.5M to solve financial reporting pain

    20 February 2026

    OpenAI deepens India push with Pine Labs fintech partnership

    19 February 2026

    Cash app adds payment links so you can get paid in DMs

    11 February 2026

    MrBeast’s company buys Gen Z fintech app Step

    9 February 2026

    Stripe Alumni Raise €30M Series A for Duna, Backed by Stripe and Adyen Executives

    5 February 2026
  • Hardware

    Joseph C Belden: Last Chance for Innovators to Earn Scaling Privileges

    20 February 2026

    At a critical time, Snap is losing a top spec executive

    20 February 2026

    Freeform Raises $67M Series B to Scale Laser AI Production

    19 February 2026

    India’s Sarvam wants to bring its AI models to phones, cars and smart glasses

    19 February 2026

    Google debuts $499 Pixel 10a

    18 February 2026
  • Media & Entertainment

    Disrupt 2026 Super Early Bird pricing expires in 1 week

    20 February 2026

    YouTube’s latest experiment brings its AI chat tool to TVs

    20 February 2026

    OpenAI, Reliance partner to add AI search to JioHotstar

    19 February 2026

    SeatGeek and Spotify are teaming up to offer concert ticket discounts within the music platform

    19 February 2026

    Audible’s new “Read & Listen” feature syncs your Kindle ebooks with audiobooks

    18 February 2026
  • Security

    Cellebrite cut off Serbia citing misuse of its phone unlocking tools. Why not others?

    20 February 2026

    FBI says ATM ‘jackpot’ attacks on the rise, hackers net millions in stolen cash

    20 February 2026

    Sex toy maker Tenga says hacker stole customer information

    19 February 2026

    Hacker conference Def Con bans three people linked to Epstein

    19 February 2026

    This former Microsoft PM thinks she can turn CyberArk around in 18 months

    18 February 2026
  • Startups

    Nominations for the Startup Battlefield 200 are now open

    21 February 2026

    The OpenAI mafia: 18 startups founded by graduates

    20 February 2026

    Nvidia deepens early-stage push into India’s AI startup ecosystem

    20 February 2026

    Kana emerges from stealth with $15M to build flexible AI agents for marketers

    19 February 2026

    A startup called Germ becomes the first private messenger to launch directly from Bluesky’s app

    19 February 2026
  • Transportation

    Lucid Motors is cutting 12% of its workforce as it pursues profitability

    21 February 2026

    New York puts the brakes on robotaxi expansion plan

    20 February 2026

    AI data center boom fuels Redwood’s energy storage business

    20 February 2026

    Tesla avoids 30-day suspension in California after removing ‘Autopilot’

    18 February 2026

    Ford turns to F1 and rewards the construction of a $30,000 electric truck

    18 February 2026
  • Venture

    Peak XV Raises $1.3B, Doubles In AI As Global India VC Competition Heats Up

    21 February 2026

    General Catalyst commits $5 billion to India over five years

    20 February 2026

    Reload wants to give your AI agents a shared memory

    20 February 2026

    This VC’s best advice for building a founding team

    19 February 2026

    SpendRule Raises $2M, Comes From Stealth To Help Hospitals Track Spending

    18 February 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Former Uber CSO Joe Sullivan explains why he ‘had to get over’ the shock of his data breach conviction
Security

Former Uber CSO Joe Sullivan explains why he ‘had to get over’ the shock of his data breach conviction

techtost.comBy techtost.com8 December 202306 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Former Uber Cso Joe Sullivan Explains Why He 'had To
Share
Facebook Twitter LinkedIn Pinterest Email

Before you sign up for Uber As Chief Security Officer in 2015, Joe Sullivan served two years as a federal prosecutor at the United States Department of Justice, where he specialized in computer piracy and IP issues. He worked on a number of high profile cases, from the first prosecution case in the US under the Digital Age Copyright Act in prosecuting a hacker who breached NASA’s Jet Propulsion Laboratory.

More than 20 years after joining the US government to help organizations defend against so-called bad guys, Sullivan found himself on the other side of the justice system.

In October 2022, a San Francisco jury found him guilty of obstruction of official process and misdemeanor (failure to report) charges. In May of this year, Sullivan was convicted on a three-year probation.

The irony is not lost on Sullivan, who spoke to TechCrunch in London this week ahead of his keynote address at the Black Hat Europe cybersecurity conference.

This precedent-setting case concerns a breach of Uber’s systems in 2016, where hackers threatened to expose the data of 50 million Uber customers and drivers. The verdict focused primarily on Uber’s decision not to report the breach to the Federal Trade Commission, as the company was ordered to report all breaches after an earlier hack of its systems in 2014 exposed the names and driver’s license numbers of 50,000 people.

The case did not go as expected for Sullivan, who was fired from Uber in 2017.

“We thought we would win the test. We barely defended because my lawyers said “no need”. I didn’t testify, so the jury never saw me. They just saw the unnamed Uber executive in a mask,” Sullivan told TechCrunch during the interview on Wednesday.

The first-of-its-kind verdict hit Sullivan hard at first. “When I missed the test last October, I was in a funk, I didn’t want to talk to anyone and I didn’t know what was going to happen in my life,” she said. “I just wanted to curl up in a ball.”

Sullivan’s case also caused concern among fellow CSOs and CISOs, several of whom wrote letters to the sentencing judge in the case, William Orrick, praising Sullivan’s actions and expressing fears that they too could face legal penalties for simply they did their job.

“Joe’s case has had a huge impact on the cybersecurity community,” read a letter, signed by more than 50 CISOs. “It has been the subject of frequent executive group conversations and panel discussions at industry seminars and a major driver of efforts to change policies and practices to make wrongful disclosure even as the legal requirement to do so remains unclear.”

These fears have lasted far beyond Sullivan’s conviction. The former Uber CSO, who now works as CEO of a non-profit organization dedicated to providing humanitarian and technological aid to the people of Ukraine, told TechCrunch that he gets calls every week from security professionals asking him if they should stay in the industry and if they have to interview for high-profile roles that come with more responsibility — and more risk.

“What I’m telling security executives right now is that they shouldn’t run away from the job — they should run toward it,” Sullivan said, noting that common anxiety among cybersecurity professionals, along with wanting to becoming The “better man” is part of the reason he wanted to start talking about the Uber data breach case.

“I realized that sharing what I’ve been through is better than not doing and healthier for me. It took me a year to say this, but this is the right way,” Sullivan told TechCrunch. “I was very bitter, but I want to be a better person. I also want to continue to be part of the security world, so I have to get over it.”

Sullivan told TechCrunch that another reason he wants to speak is because there have been “100 webinars, by 100 lawyers, saying ‘you’re not going to end up like Joe if you have insurance, if you bring legal and PR into the room or if you have a breach liability policy’.

“We did all these things [at Uber]Sullivan said. “We had insurance. there was a data breach policy. we met in public relations and the CEO [Travis Kalanick] signed everything, including the dollar amount,” he added, referring to the $100,000 payment made to the two young men who discovered the vulnerability that led to the Uber breach in 2016.

When asked if he thought Uber’s then-CEO should have been held responsible, Sullivan said, “I don’t think anybody did anything wrong at the end of the day.”

“Uber wouldn’t exist today — in fact, we’d still be taking taxis — if it weren’t for it [Kalanick] and his sheer power,” Sullivan added. “From above, he drove some change into the world. However, the downside, his philosophy was that the person who threw the first punch wins the fight.”

Fixing a broken industry

In what Sullivan describes as “the biggest irony of his career,” part of his role at the Justice Department involved him working closely with organizations in Silicon Valley to encourage more cooperation with the government. “That was the story of my career. trying to get the public and private sectors to work together.”

Sullivan believes that going forward, this public-private partnership, along with strong regulation, is the only way to fix the “broken” cybersecurity industry.

“When I joined, [Uber] it had the worst security of any $40 billion company, and it can no longer fly in the world. If you’re going to sell a product, your security has to be pretty good the day you sell it,” Sullivan said. “I could be very bitter about the idea of ​​government regulation since I was regulated, but I also think we need it to make the Internet work well in the future.”

Sullivan praised the US Securities and Exchange Commission inbound data breach disclosure rules, which goes into effect on December 15, noting that while it’s not perfect, it’s a lot better than having zero guidance. “We can pick apart the details as much as we want, but this is the right way to do it,” he said. “I seem to be the person who criticizes the SEC less than everyone else because I think they should be praised for trying to set rules.”

As for CSOs and CISOs, many of whom still worry about being held personally responsible for security failures in their organization, Sullivan believes now is the time to speak up to shape any future regulation.

“We have to pull ourselves together, we have to learn the political side of it, and we have to learn how to make our voices heard,” Sullivan told TechCrunch. “I think we need to develop leaders who can be real leaders of society who are experts in our profession.”

breach conviction CSO cyber security data data breach doc Exclusive explains Joe Joe Sullivan Ministry of Justice shock Sullivan Uber
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDNA companies should be given the death penalty for hacking
Next Article Avail Launches AI Briefing Tool to Help Hollywood Executives Keep Up with Script Coverage
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Lucid Motors is cutting 12% of its workforce as it pursues profitability

21 February 2026

Peak XV Raises $1.3B, Doubles In AI As Global India VC Competition Heats Up

21 February 2026

Great news for xAI: Grok is now very good at answering questions about Baldur’s Gate

21 February 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Nominations for the Startup Battlefield 200 are now open

21 February 2026

Lucid Motors is cutting 12% of its workforce as it pursues profitability

21 February 2026

Peak XV Raises $1.3B, Doubles In AI As Global India VC Competition Heats Up

21 February 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

InScope raises $14.5M to solve financial reporting pain

20 February 2026

OpenAI deepens India push with Pine Labs fintech partnership

19 February 2026

Cash app adds payment links so you can get paid in DMs

11 February 2026
Startups

Nominations for the Startup Battlefield 200 are now open

The OpenAI mafia: 18 startups founded by graduates

Nvidia deepens early-stage push into India’s AI startup ecosystem

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.