惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
有赞技术团队
有赞技术团队
博客园_首页
H
Help Net Security
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
The Cloudflare Blog
腾讯CDC
Jina AI
Jina AI
Last Week in AI
Last Week in AI
月光博客
月光博客
博客园 - 叶小钗
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
爱范儿
爱范儿
N
Netflix TechBlog - Medium
F
Fortinet All Blogs

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
Uber's Former Chief on Trail | iubenda
Jessica Ryder · 2022-09-14 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

Joe Sullivan, Uber’s former security chief, goes on trial this week in what is believed to be the first instance of an executive facing criminal charges in connection with a data breach.

The US District Court in San Francisco will hear arguments on whether Sullivan, the ride-sharing company’s former chief of security, neglected to properly disclose a 2016 data breach that affected 57 million Uber riders and drivers worldwide. At a time when allegations of ransomware attacks have increased, and cybersecurity insurance rates have skyrocketed, the case might set a significant precedent regarding the accountability of US security personnel and executives for how the organizations for which they work manage cybersecurity crises.

The Background

Back in November of 2017, the breach first came to light. Dara Khosrowshahi, Uber’s chief executive, revealed that hackers gained access to 600,00 US driver’s license plates, names, emails, and phone numbers of 57 million Uber riders and drivers. 

Public disclosures such as Khosrowshahi’s are required by law in several US states, with most legislation requiring the notification to be issued “in the most expedient time possible and without unreasonable delay”.

However, Khosrowshahi’s announcement included an admission: the information had been exposed for a whole year beforehand. Khosrowshahi claimed at the time that the business had investigated the delay and removed two officials, one of whom was Sullivan, who had headed the response to the breach.

Uber paid $148 million in a nationwide settlement with 50 state attorneys general in 2018 for failing to disclose the data breach. The two hackers pled guilty in 2019 to hacking Uber and then extorting the company’s “bug bounty” security research program. The Department of Justice charged Sullivan with a crime in 2020.

The Trail

According to the Justice Department lawsuit, only Sullivan and former Uber CEO Travis Kalanick were aware of the entire scope of the hack. They played a role in the decision to classify it as an approved disclosure through the bug bounty program. However, as the New York Times first reported, the security profession is divided on whether Sullivan should be held entirely accountable for the attack. Some have questioned if the role of other corporate officials and the board of directors should also be probed, while others believe Sullivan’s involvement was obvious.

The trial will take place as reports of ransomware attacks increase. According to the threat intelligence firm SonicWall, ransomware assaults in the United States climbed by more than 95% in 2021. Many of those assailants targeted hospitals and schools. Over the Labor Day weekend, hackers launched a cyber-attack on the Los Angeles Unified School District, the country’s second-largest school district.