{
  "id": "case-uber-sullivan",
  "slug": "uber-extortion-coverup-sullivan",
  "title": "U.S. v. Joseph Sullivan (Uber Breach Extortion Cover-up)",
  "summary": "Historic federal criminal prosecution of former Uber Chief Security Officer Joseph Sullivan for obstruction of justice and misprision of a felony after concealing a massive breach of 57 million user and driver records by paying $100,000 in Bitcoin through a bug bounty program under non-disclosure agreements.",
  "case_number": "3:20-cr-00337-WHO",
  "court": "U.S. District Court for the Northern District of California",
  "district": "N.D. Cal.",
  "country": "United States",
  "opened_at": "2020-08-20",
  "status": "sentenced",
  "victim_sector": "Technology & Transportation",
  "victim_country": "United States",
  "loss_amount_usd": 148000000,
  "loss_amount_note": "Uber paid $148 million nationwide settlement to all 50 states and D.C.",
  "first_seen_at": "2016-11-14T00:00:00Z",
  "last_updated_at": "2026-10-06T10:00:00Z",
  "actor_slug": "unattributed-cybercrime",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Adversaries acquired access credentials for Uber AWS cloud storage infrastructure from code repositories left publicly accessible on GitHub by Uber software engineers.",
      "evidence_locator": "DOJ Criminal Indictment \u00b6 14, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Indictment: U.S. v. Sullivan",
      "source_url": "https://www.justice.gov/usao-ndca/pr/former-chief-security-officer-uber-convicted-federal-court-obstruction-justice-and",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1530",
      "evidence_excerpt": "Threat actors accessed Uber private Amazon S3 cloud storage buckets housing unencrypted databases containing 57 million customer records and 600,000 driver license numbers.",
      "evidence_locator": "DOJ Criminal Indictment \u00b6 16, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Indictment: U.S. v. Sullivan",
      "source_url": "https://www.justice.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2016-11-14",
      "description": "Extortionists email Sullivan stating they found a major vulnerability and extracted Uber database."
    },
    {
      "event_type": "payment",
      "event_date": "2016-12-08",
      "description": "Uber pays $100,000 in Bitcoin through HackerOne bug bounty platform disguised as whitehat fee."
    },
    {
      "event_type": "disclosure",
      "event_date": "2017-11-21",
      "description": "New Uber executive leadership publicly discloses the breach to FTC and state regulators."
    },
    {
      "event_type": "conviction",
      "event_date": "2022-10-05",
      "description": "Federal jury finds Sullivan guilty of obstruction of FTC proceedings and misprision of a felony."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Publicly exposed GitHub code repository containing hardcoded Amazon Web Services (AWS) administrative credentials left by Uber engineering personnel.",
    "blast_radius": "57 million customer and driver records exfiltrated, leading to federal criminal obstruction and misprision convictions for Chief Security Officer Joseph Sullivan and a $148 million nationwide settlement across all 50 states.",
    "kill_chain": [
      {
        "phase": "Credential Exposure",
        "title": "Public Code Repository Credential Harvesting",
        "description": "Extortionists discovered unencrypted AWS administrative API keys committed into public GitHub repositories maintained by Uber software engineers.",
        "technical_artifacts": [
          "Exposed AWS IAM access keys",
          "Public GitHub commits"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Cloud Storage Ingress",
        "title": "Amazon S3 Bucket Data Discovery",
        "description": "Adversaries utilized the stolen IAM credentials to query private Amazon S3 cloud buckets housing 57 million customer records and 600,000 driver license numbers.",
        "technical_artifacts": [
          "AWS S3 API queries",
          "Unencrypted database backups"
        ],
        "mitre_technique_id": "T1530"
      },
      {
        "phase": "Extortion Contact",
        "title": "Demand for $100,000 Payment",
        "description": "Adversaries emailed Uber security executives stating they possessed database extracts and demanded $100,000 to destroy the stolen data.",
        "technical_artifacts": [
          "Extortion communications",
          "Data proof samples"
        ],
        "mitre_technique_id": "T1651"
      },
      {
        "phase": "Covert Settlement",
        "title": "Bug Bounty Platform Payment Under NDA",
        "description": "Uber security leadership funneled $100,000 in Bitcoin through the HackerOne bug bounty platform, requiring the hackers to sign non-disclosure agreements falsely stating no data was downloaded.",
        "technical_artifacts": [
          "HackerOne bounty payment",
          "Falsified whitehat agreements"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Legal Repercussions",
        "title": "Federal Obstruction Conviction",
        "description": "Following disclosure by new executive leadership, federal prosecutors indicted and convicted Sullivan for concealing the breach from the Federal Trade Commission.",
        "technical_artifacts": [
          "DOJ trial exhibits",
          "Federal jury guilty verdict"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Implement automated pre-commit secret detection hooks to prevent cloud keys from ever reaching code repositories.",
      "Never utilize bug bounty platforms or non-disclosure agreements to conceal criminal extortion demands.",
      "Enforce mandatory executive legal escalation protocols upon confirmation of consumer data exfiltration.",
      "Maintain strict principle-of-least-privilege IAM roles with time-bound temporary session credentials."
    ]
  }
}