U.S. v. Joseph Sullivan (Uber Breach Extortion Cover-up)
Key Facts
- Legal Status: SENTENCED in U.S. District Court for the Northern District of California.
- Primary Target Sector: Technology & Transportation.
- Documented Financial Loss: $148.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Publicly exposed GitHub code repository containing hardcoded Amazon Web Services (AWS) administrative credentials left by Uber engineering personnel.
Operational & Financial Fallout
57 million customer and driver records exfiltrated, leading to federal criminal obstruction and misprision convictions for Chief Security Officer Joseph Sullivan and a $148 million nationwide settlement across all 50 states.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Publicly exposed GitHub code repository containing hardcoded Amazon Web Services (AWS) administrative credentials left by Uber engineering personnel.
Adversary Kill Chain Flow
5 Documented PhasesExtortionists discovered unencrypted AWS administrative API keys committed into public GitHub repositories maintained by Uber software engineers.
Adversaries utilized the stolen IAM credentials to query private Amazon S3 cloud buckets housing 57 million customer records and 600,000 driver license numbers.
Adversaries emailed Uber security executives stating they possessed database extracts and demanded $100,000 to destroy the stolen data.
Uber security leadership funneled $100,000 in Bitcoin through the HackerOne bug bounty platform, requiring the hackers to sign non-disclosure agreements falsely stating no data was downloaded.
Following disclosure by new executive leadership, federal prosecutors indicted and convicted Sullivan for concealing the breach from the Federal Trade Commission.
57 million customer and driver records exfiltrated, leading to federal criminal obstruction and misprision convictions for Chief Security Officer Joseph Sullivan and a $148 million nationwide settlement across all 50 states.
Procedural & Incident Timeline
Extortionists email Sullivan stating they found a major vulnerability and extracted Uber database.
Uber pays $100,000 in Bitcoin through HackerOne bug bounty platform disguised as whitehat fee.
New Uber executive leadership publicly discloses the breach to FTC and state regulators.
Federal jury finds Sullivan guilty of obstruction of FTC proceedings and misprision of a felony.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Adversaries acquired access credentials for Uber AWS cloud storage infrastructure from code repositories left publicly accessible on GitHub by Uber software engineers." | DOJ Criminal Indictment ¶ 14, Page 6 | reviewed |
| T1530 | "Threat actors accessed Uber private Amazon S3 cloud storage buckets housing unencrypted databases containing 57 million customer records and 600,000 driver license numbers." | DOJ Criminal Indictment ¶ 16, Page 7 | reviewed |