Case file · UBER 2016

How the Uber breach happened: a cloud key left in the code, and a $100,000 cover-up

Published 2026-09-29 · 5 min read · Missing control: No secret keys in code

The 2016 Uber hackers did not break any encryption. They logged into employees' code accounts with passwords recycled from an old leak at another company, and found a key to Uber's cloud storage sitting in the code.[1] This case file covers how that key exposed data on 57 million people, how the breach was paid off and hidden for a year, and the control that would have kept the door shut.

What happened

On November 14, 2016, Uber's chief security officer, Joe Sullivan, received an email from a hacker saying they had taken a large amount of Uber data and wanted a six-figure payment.[1][2] The files covered about 57 million riders and drivers, including names, email addresses, phone numbers and roughly 600,000 driver's license numbers.[1][2]

The timing was awkward. The Federal Trade Commission was already investigating Uber over an earlier 2014 breach, and Sullivan had given sworn testimony to the agency about Uber's data security only days before the email arrived.[3][4] Instead of reporting the new breach, Uber paid the 2 hackers $100,000 in bitcoin in December 2016 through its bug bounty program, the scheme companies use to reward researchers who report flaws responsibly. The hackers signed agreements stating, falsely, that they had not taken or kept any data.[2][3]

Uber's program normally capped rewards at $10,000.[1] Uber's security team tracked down the 2 hackers' real identities in December 2016, but the breach stayed secret from the public and regulators until new management disclosed it in November 2017, about a year later.[1][2]

How they got in

According to trial testimony from an Uber security manager, the attackers started with usernames and passwords exposed years earlier in a large breach at LinkedIn. Some Uber engineers had reused those same passwords on their accounts at GitHub, a service where developers store and share code.[1]

Inside Uber's private code, the attackers found an access key for Uber's Amazon cloud storage. An access key works like a password for a program rather than a person, and whoever holds it can use it from anywhere. That key opened a storage bucket holding more than 200 files of user and driver data, which the attackers downloaded.[1]

So 2 weaknesses lined up: reused passwords let outsiders into the code, and a secret left inside the code turned a look at source files into a copy of the customer database.

What it cost

The cover-up turned out to be more expensive than the breach. In September 2018 Uber agreed to pay $148 million to settle claims from all 50 states and Washington, D.C., which said it had broken breach notification laws by waiting more than a year to tell people.[5] Uber also fired Sullivan and a deputy over their handling of the incident.[5]

The 2 hackers pleaded guilty to computer fraud conspiracy on October 30, 2019. Prosecutors said that after the Uber payout, they breached another company, Lynda.com, and tried to ransom that data too.[2][3]

On October 5, 2022, a federal jury convicted Sullivan of obstructing the FTC's proceedings and of misprision of a felony, which means actively concealing a crime he knew about.[2] In May 2023 a judge sentenced him to 3 years of probation, a $50,000 fine and 200 hours of community service. Prosecutors had asked for 15 months in prison.[4] The Ninth Circuit upheld the conviction on March 17, 2025.[6] It was widely seen as the first time a corporate security chief was criminally convicted over a breach response.

The missing control

The missing control: keeping secret keys out of code. Passwords, access keys and tokens that let software reach live data should be stored in a locked-down secrets vault, not written into files that dozens of developers and any compromised account can read.

If the storage key had not been in the code, the reused passwords would have exposed source files but not the personal data of 57 million people. Reused passwords were the first failure, and multi-factor sign-in on developer accounts would have blocked that step too. But secrets in code are the kind of mistake that turns a small intrusion into a headline. The second lesson is just as plain: a breach you hide becomes a much larger legal problem than the one you report.

What to do in your business

Watch the case
Uber paid hackers and called it a bug bountyDrops 2026-11-11
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Courthouse News Service: Former Uber security chief details hunt for hackers behind 2016 data breach
  2. U.S. Attorney's Office, Northern District of California: Former chief security officer of Uber convicted of federal charges for covering up data breach
  3. U.S. Attorney's Office, Northern District of California: Former chief security officer of Uber charged with obstruction of justice
  4. KTVU: Former Uber exec sentenced for covering up data breach
  5. CyberScoop: Uber data breach settlement, $148 million
  6. Daily Journal: 9th Circuit upholds conviction of former Uber security chief