CASE DOSSIER sentenced

U.S. v. Joseph Sullivan (Uber Breach Extortion Cover-up)

Docket: 3:20-cr-00337-WHO Court: U.S. District Court for the Northern District of California Opened: 2020-08-20 Sector: Technology & Transportation

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$148.0 million
Uber paid $148 million nationwide settlement to all 50 states and D.C.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SENTENCED in U.S. District Court for the Northern District of California.
  • Primary Target Sector: Technology & Transportation.
  • Documented Financial Loss: $148.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Historic federal criminal prosecution of former Uber Chief Security Officer Joseph Sullivan for obstruction of justice and misprision of a felony after concealing a massive breach of 57 million user and driver records by paying $100,000 in Bitcoin through a bug bounty program under non-disclosure agreements.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Publicly exposed GitHub code repository containing hardcoded Amazon Web Services (AWS) administrative credentials left by Uber engineering personnel.

Operational & Financial Fallout

57 million customer and driver records exfiltrated, leading to federal criminal obstruction and misprision convictions for Chief Security Officer Joseph Sullivan and a $148 million nationwide settlement across all 50 states.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Publicly exposed GitHub code repository containing hardcoded Amazon Web Services (AWS) administrative credentials left by Uber engineering personnel.

Adversary Kill Chain Flow

5 Documented Phases
1
Credential Exposure Public Code Repository Credential Harvesting
MITRE ATT&CK T1078 →

Extortionists discovered unencrypted AWS administrative API keys committed into public GitHub repositories maintained by Uber software engineers.

Artifacts & Tooling: Exposed AWS IAM access keys Public GitHub commits
2
Cloud Storage Ingress Amazon S3 Bucket Data Discovery
MITRE ATT&CK T1530 →

Adversaries utilized the stolen IAM credentials to query private Amazon S3 cloud buckets housing 57 million customer records and 600,000 driver license numbers.

Artifacts & Tooling: AWS S3 API queries Unencrypted database backups
3
Extortion Contact Demand for $100,000 Payment
MITRE ATT&CK T1651 →

Adversaries emailed Uber security executives stating they possessed database extracts and demanded $100,000 to destroy the stolen data.

Artifacts & Tooling: Extortion communications Data proof samples
4
Covert Settlement Bug Bounty Platform Payment Under NDA
MITRE ATT&CK T1078 →

Uber security leadership funneled $100,000 in Bitcoin through the HackerOne bug bounty platform, requiring the hackers to sign non-disclosure agreements falsely stating no data was downloaded.

Artifacts & Tooling: HackerOne bounty payment Falsified whitehat agreements
5
Legal Repercussions Federal Obstruction Conviction
MITRE ATT&CK T1078 →

Following disclosure by new executive leadership, federal prosecutors indicted and convicted Sullivan for concealing the breach from the Federal Trade Commission.

Artifacts & Tooling: DOJ trial exhibits Federal jury guilty verdict
Real-World Blast Radius & Operational Fallout

57 million customer and driver records exfiltrated, leading to federal criminal obstruction and misprision convictions for Chief Security Officer Joseph Sullivan and a $148 million nationwide settlement across all 50 states.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Implement automated pre-commit secret detection hooks to prevent cloud keys from ever reaching code repositories.
✓ Never utilize bug bounty platforms or non-disclosure agreements to conceal criminal extortion demands.
✓ Enforce mandatory executive legal escalation protocols upon confirmation of consumer data exfiltration.
✓ Maintain strict principle-of-least-privilege IAM roles with time-bound temporary session credentials.

Procedural & Incident Timeline

2016-11-14 incident

Extortionists email Sullivan stating they found a major vulnerability and extracted Uber database.

2016-12-08 payment

Uber pays $100,000 in Bitcoin through HackerOne bug bounty platform disguised as whitehat fee.

2017-11-21 disclosure

New Uber executive leadership publicly discloses the breach to FTC and state regulators.

2022-10-05 conviction

Federal jury finds Sullivan guilty of obstruction of FTC proceedings and misprision of a felony.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Adversaries acquired access credentials for Uber AWS cloud storage infrastructure from code repositories left publicly accessible on GitHub by Uber software engineers." DOJ Criminal Indictment ¶ 14, Page 6 reviewed
T1530
"Threat actors accessed Uber private Amazon S3 cloud storage buckets housing unencrypted databases containing 57 million customer records and 600,000 driver license numbers." DOJ Criminal Indictment ¶ 16, Page 7 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Joseph Sullivan (Uber Breach Extortion Cover-up), No. 3:20-cr-00337-WHO (U.S. District Court for the Northern District of California 2020), https://cybercaselibrary.com/cases/uber-extortion-coverup-sullivan/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/uber-extortion-coverup-sullivan" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>