The Uber data breach of 2016 exposed records of 57 million riders and drivers, and Uber hid it for about a year by paying the hackers $100,000 through its bug bounty program. In 2017 new CEO Dara Khosrowshahi disclosed it publicly. In 2022 a federal jury convicted Uber's former security chief, Joe Sullivan, of obstruction and misprision of a felony.
What happened in the 2016 Uber data breach?
In October 2016, two hackers broke into Uber's systems and took records on about 57 million users, including names and phone numbers, plus 600,000 driver's license numbers. They told Uber's security team what they had and asked for payment.
Uber's security chief, Joe Sullivan, arranged to pay the hackers $100,000 in bitcoin in December 2016 through the company's bug bounty program, and had them sign nondisclosure agreements, according to Cybersecurity Dive. At the time, the Federal Trade Commission was already investigating Uber over a separate 2014 breach, and the 2016 incident was not disclosed to the agency, state regulators or affected users.
How did Uber disclose the breach?
Uber disclosed the breach on November 21, 2017, in a post by CEO Dara Khosrowshahi titled "2016 Data Security Incident." Khosrowshahi had become CEO that August and fired Sullivan after finding that he had tried to mislead him about the breach, as Khosrowshahi later testified at trial.
The new CEO had three paths, and each carried a different reputational cost.
| Path | What it meant | Risk |
|---|---|---|
| Continue the concealment | Rely on the hackers' nondisclosure agreements | A continuing legal violation |
| Disclose to regulators only | Negotiate quietly with the FTC and state attorneys general | A later leak looks like a second cover-up |
| Disclose publicly | Publish the facts under the CEO's name | An immediate reputational hit |
Khosrowshahi chose public disclosure, and most coverage at the time treated the new CEO as separate from the old regime. That reading did not protect the executives involved in the original concealment.
What did the Uber breach cost?
The breach cost Uber a $148 million settlement with all 50 state attorneys general, an expanded FTC consent order, and criminal exposure for its former security chief. The timeline below shows how the case ran.
| Date | Event |
|---|---|
| November 21, 2017 | Khosrowshahi discloses the 2016 breach publicly |
| September 26, 2018 | Uber agrees to a $148 million settlement with 50 state attorneys general |
| 2018 | The FTC expands its existing consent order to cover the 2016 breach |
| October 2019 | The two hackers plead guilty to federal charges |
| August 2020 | Federal prosecutors charge Sullivan with obstruction and misprision of a felony |
| October 5, 2022 | A federal jury convicts Sullivan on both counts |
| May 4, 2023 | Judge William Orrick sentences Sullivan to three years of probation, 200 hours of community service and a $50,000 fine |
Why did the Sullivan conviction matter?
The Sullivan conviction mattered because it was the first time a corporate executive was criminally prosecuted over a data breach, according to the Daily Journal's report on the sentencing. Judge Orrick gave probation, not the 15 months the government sought, because the case was the first of its kind, and he said future similar offenses would bring prison time.
The Ninth Circuit later upheld the conviction on appeal. The court case turned on Sullivan's handling of the FTC investigation, and on the use of a bug bounty program to pay hackers for silence. Security officers now have personal exposure for how they handle a breach, not only the company.
What do the SEC breach disclosure rules require now?
The SEC's cybersecurity rules require public companies to file a Form 8-K under Item 1.05 within four business days after determining that a cybersecurity incident is material. The rules were adopted on July 26, 2023, and most companies had to comply from December 18, 2023, according to Cooley's summary of the rule.
The four days run from the materiality determination, not from discovery, so the clock starts when the company decides the incident matters to investors. Public companies should review disclosure timing with securities counsel.
What should a company do when it discovers a breach?
A company that discovers a breach should disclose it promptly under the CEO's name, quantify the exposure, and hold accountable anyone who concealed it. The Uber case shows each move.
Name the number of affected people, the data types and the remediation steps, because vague disclosure invites reporters to fill the gap. Use a named executive instead of a spokesperson, as Khosrowshahi did. Do not pay for silence, and do not route a payment so that it looks routine. Consult counsel on regulators and law enforcement before the first public statement.
For the structure of a holding statement, see the Crisis Statement Template and the seven-move response in the crisis communications pillar. A parallel case is covered in product recall communications. For help with a breach response, see 5W's crisis PR practice.
Where can you read more on Uber's reputation?
Uber's reputation arc is covered across this site and Everything-PR: my 2015 Uber analysis, the 2018 reputation rebuild, Everything-PR's Uber public relations guide and its Greyball scandal case.
Originally published November 2017. Updated October 2026.
Ronn Torossian is the founder and chairman of 5W AI Communications. He is the publisher of Everything-PR and the author of two best-selling editions of For Immediate Release.
