September 28, 2022

Uber Boss Testifies He ‘Could Not Trust’ Ex-Security Chief

Dara Khosrowshahi is a star witness at the trial of Joe Sullivan, who has been accused of obstructing justice for failing to disclose the 2016 breach.

Dara Khosrowshahi, Uber’s chief executive, said in court on Friday that he had fired Joe Sullivan, the former Uber security chief who is on trial over a 2016 security breach, because he could no longer trust him.

“He was my chief security officer, and I could not trust his judgment anymore,” Mr. Khosrowshahi said of Mr. Sullivan in a San Francisco federal court. “I thought the decision not to disclose” the breach “was the wrong decision.”

Mr. Khosrowshahi was a star witness at the trial of Mr. Sullivan, who has been accused of obstructing justice for failing to disclose the 2016 breach, which affected the Uber accounts of more than 57 million riders and drivers. Mr. Sullivan’s lawyers have argued that Uber’s management team, led by Mr. Khosrowshahi, unfairly targeted him as the company worked to recast its image after the freewheeling reign of its former chief executive, Travis Kalanick.

But Mr. Khosrowshahi painted a different picture during his testimony, which came a day after Uber said it was investigating a new breach of its network.

He said that he fired Mr. Sullivan in 2017 because Mr. Sullivan misled him in an email about the 2016 incident. Mr. Khosrowshahi added that Uber later reported the incident to regulators because it was in the best interest of the public.

The outcome of the trial could change how professionals handle security incidents, experts have said. Many believe that Mr. Sullivan is the first company executive to face criminal prosecution over response to a data breach.

The hack was discovered in 2016, while the Federal Trade Commission was investigating a previous data breach at Uber. Mr. Sullivan received an email from a hacker claiming he had found a major security vulnerability in Uber’s online systems and that he was able to download information from the company.

About a day later, Mr. Sullivan learned that the hacker had downloaded a database containing the personal data of about 600,000 Uber drivers and additional personal information associated with 57 million riders and drivers, according to court testimony and documents.

Mr. Sullivan and his team eventually referred the hacker and an accomplice to Uber’s bug bounty program, a common way of paying security researchers to identify and report security vulnerabilities. Through the program, Uber paid the hackers $100,000 and had them sign nondisclosure agreements.

Uber did not publicly disclose the incident or inform the F.T.C. until after Mr. Khosrowshahi took over as chief executive in the fall of 2017. The two hackers eventually pleaded guilty to hacking.

Most states require companies to disclose security breaches if hackers download personally identifiable data and a certain number of users are affected. There is no federal law requiring companies or executives to reveal breaches to regulators.

Federal prosecutors accused Mr. Sullivan of concealing a felony for failing to disclose the breach to the F.T.C. while the company was already under investigation by the agency.

“A lot of people are really scared about what prosecuting Joe Sullivan means for security professionals,” said Whitney Merrill, a longtime security and privacy professional and lawyer who previously spent time at the F.T.C. “But I think this is a lesson for any high level official who must communicate with the government: You can’t treat communications with the government like it’s no big deal.”

Mr. Khosrowshahi said that after he took over as Uber’s chief executive, he learned about the data breach and asked Mr. Sullivan to provide additional details over email.

Mr. Sullivan sent an email to Mr. Khosrowshahi a few days later, according to court testimony and documents. Later, after asking outside firms to investigate the matter, Mr. Khosrowshahi learned the email did not acknowledge that the hackers had downloaded personal information about drivers and riders.

He said he also learned that the email had not disclosed that Mr. Sullivan and his team had paid the hackers $100,000, an unusually large sum for the big bounty program, Mr. Khosrowshahi said.

“Based on the facts that I had learned, we had an obligation to disclose” the incident to regulators, he said on the stand. “These security issues are serious, and if there is the potential of an obligation for disclose, you have to. People are affected by this.”

Uber discovered that it had been breached again on Thursday when a hacker announced their presence in the company’s workplace messaging system, Slack. The hacker claimed to have access to numerous internal systems used by the company to manage its data, code and communications. Uber shut down Slack and other corporate systems on Thursday evening as it investigated the extent of the breach, and notified law enforcement.

On Friday, Uber said it had found no evidence that the hacker had gained access to “sensitive user data” like trip history. All of its services, including its flagship app and Uber Eats, its food delivery service, were functioning, the company said.

What People Read

Yvonne Orji Reflects on the End of ‘Insecure,’ and Tells T a Joke

The comedian looks back on her years working on the career-defining show and demonstrates her trademark wit.

YouTube Opens More Pathways for Creators to Make Money on the Platform

The video platform will let more creators earn payments and place ads in Shorts, its TikTok competitor, according to audio from an internal meeting.

Yankees Close In on Division Title, but Still Have Trust Issues

Frankie Montas, Aroldis Chapman and Aaron Hicks are question marks for a team that is on the verge of clinching a first-round bye.

Yankees Clinch a First-Round Bye as Judge’s Wait Continues

A win over Toronto gave the Yankees the American League East title, but Aaron Judge remained stuck at 60 home runs.

Woman Gets 4 Months After Shoving Flight Attendant, Spitting on a Passenger

Kelly Pichardo, 32, will also have to pay more than $9,000 to American Airlines for the altercation, which came as incidents involving unruly passengers unnerved airline workers and the public.

Just For You

How the Passage of Time Softened the Fury Over Diana’s Death

A quarter-century ago Princess Diana’s shocking death provoked outrage at the royal family. Queen Elizabeth’s passing, in contrast, has been draped in civility and respect.

White House Student Loan Forgiveness Could Cost About $400 Billion

The estimate by the nonpartisan Congressional Budget Office gauged the cost over 30 years, though the bulk of the effects to the economy would be felt over the next decade.

Kushner’s Company Reaches $3.25 Million Settlement in Maryland Lawsuit

The apartment company charged illegal fees and failed to adequately address leaks, mold and rodent infestations in its properties, the Maryland attorney general said.

As Trump’s Legal Woes Mount, So Do Financial Pressures on Him

The lawsuit filed by New York’s attorney general is the latest indication of how an array of investigations is affecting the former president’s business and personal wealth.

N.Y. Attorney General Accuses Trump of ‘Staggering’ Fraud in Lawsuit

Attorney General Letitia James of New York filed a sweeping lawsuit on Wednesday that accused Donald J. Trump, his family business and three of his children of lying to lenders and insurers by fraudulently overvaluing his assets by billions of dollars.

Why Candidates Owe Voters Full Medical Transparency

The principal intent of campaigns is to give voice to the candidates’ positions on major issues. When casting their ballots, voters consider personality, party allegiance, character traits and other factors.

Russians Are Terrified, and Have Nowhere to Turn

In the days since Vladimir Putin announced a “partial mobilization,” clearing the way for hundreds of thousands of men to be conscripted into his failing war effort, we’ve fielded tens of thousands of messages like these.

How Seriously Should We Take Putin’s Nuclear Threat in Ukraine?

Across almost eight decades the possibility of nuclear war has been linked to complex strategic calculations, embedded in command-and-control systems, subject to exhaustive war games.

Recent

How the Passage of Time Softened the Fury Over Diana’s Death

A quarter-century ago Princess Diana’s shocking death provoked outrage at the royal family. Queen Elizabeth’s passing, in contrast, has been draped in civility and respect.

This Might Not Be a Cold War, but It Feels Like One

Even at their worst moments, the Americans and the Soviets kept talking. Today, U.S.-China contacts are scarce, while Beijing and Moscow move closer together.

Apple Extends Reach With $800 Watch, as New iPhone Inches Along

The Apple Watch Ultra is aimed at endurance athletes, a market dominated by Garmin. Apple also introduced updated AirPods.