
A former CSO is accused of trying to conceal Uber’s involvement in a 2016 data breach by paying the hackers $100K in Bitcoin.
Joseph Sullivan, a former Chief Security Officer at Uber, allegedly tried to cover up a 2016 hack of sensitive data by funneling a hush money payment of $100,000 in Bitcoin through a bug bounty program.
The hackers had obtained the drivers’ license numbers of roughly 600,000 Uber drivers as well as private information for roughly 57 million users.
According to an Aug. 20 announcement from the U.S. Department of Justice (DoJ), Sullivan has been charged with obstruction of justice and misprision of a felony in connection with the 2016 hack. The former CSO is accused of taking “deliberate steps to conceal, deflect, and mislead” the Federal Trade Commission (FTC) regarding the data breach and the associated $100,000 Bitcoin (BTC) hush money payment.
The DoJ accused him of preventing knowledge of the breach from being reported to the FTC by funneling the Bitcoin hush money through a bug bounty program. Ordinarily such programs are used for legitimate payments to ‘white hat’ hackers who report on a company’s security issues, not those who actually obtain unauthorized data.
“We will not tolerate illegal hush money payments,” said U.S. Attorney David Anderson. “Silicon Valley is not the Wild West.”
The agency also alleges Sullivan tried to conceal the company’s involvement in the breach by asking the hackers to sign non-disclosure agreements falsely stating they had not obtained any personal data from Uber — even while they were anonymous. When an investigation unmasked two of the individuals responsible for the breach, the DoJ alleges Sullivan still asked for the hackers to sign NDAs rather than report them.
Two of the hackers involved in the Uber breach pleaded guilty to charges of computer fraud conspiracy in October and are now awaiting sentencing.
Negotiating with criminals
Companies are increasingly being forced to deal directly with cyber criminals — though most remain within the law while doing so. Representatives from U.S.-based corporate travel firm CWT were able to negotiate a 50% discount from hackers demanding a $10 million payment after they stole sensitive files from the company in July.
More recently, the University of California conducted a week-long negotiation with a NetWalker ransomware group after it shut down seven of the institution’s servers. The university was able to convince the group to come down from $3 million to $1 million using respectful and flattering language in their chats.
Source: , CoinTelegraph

Articles listed with Cash Tech News as the author are either general information, or may have been imported from another website, to bring our readers a rich media experience that encompasses articles that we find interesting, as well as those curated by others.
The views and opinions expressed here are for informational purposes only, and should not be confused with professional financial advice. These opinions are solely those of the author and do not necessarily reflect the views of CashTechNews.com. Every investment and trade involves risk. You should conduct your own research, and contact your professional financial advisor before making any investment.
Corrections, feedback, and ideas should be submitted through the website contact form.